Vulnerability CVE-2023-52251


Published: 2024-01-25

Description:
An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages.

See advisories in our WLB2 database:
Topic
Author
Date
High
Kafka UI 0.7.1 Command Injection
h00die-gr3y
20.02.2024

Type:

CWE-78

(Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') )

 References:
https://github.com/BobTheShoplifter/CVE-2023-52251-POC

Copyright 2024, cxsecurity.com

 

Back to Top