Security Advisory regarding TIBCO Messaging - Apache Kafka Distribution

Security Advisory regarding TIBCO Messaging - Apache Kafka Distribution

book

Article ID: KB0108093

calendar_today

Updated On:

Products Versions
TIBCO Messaging - Schema Repository for Apache Kafka - Enterprise Edition 1.0

Description

TIBCO Messaging - Apache Kafka Distribution - Schema Repository Vulnerable
to CSRF Attacks

  Original release date: November 6, 2018
  Last revised:
  Source: TIBCO Software Inc.

Description

  The component listed above contains a vulnerability which may allow an
  attacker to perform cross-site request forgery (CSRF) attacks.


Impact

  The impact of this vulnerability includes the theoretical possibility that
  an attacker could gain full access to the configuration of message schemas
  used with an Apache Kafka deployment. With such access, the attacker could
  also configure Apache Kafka communications to fail.

  CVSS v3 Base Score: 7.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)

Issue/Introduction

Security Advisory regarding TIBCO Messaging - Apache Kafka Distribution

Environment

Systems Affected TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition version 1.0.0 TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition version 1.0.0 The following components are affected: * Schema repository server (tibschemad)

Resolution

Solution

  TIBCO has released updated versions of the affected components which address
  these issues.

  For each affected system, update to the corresponding software versions:

  TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community
    Edition version 1.0.0 update to version 1.0.1 or higher

  TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise
    Edition version 1.0.0 update to version 1.0.1 or higher

Additional Information

References

  http://www.tibco.com/services/support/advisories
  CVE-2018-12413