Kafbat UI is a web user interface for managing Apache Kafka clusters. An unsafe deserialization vulnerability in version 1.0.0 allows any unauthenticated user to execute arbitrary code on the server. Version 1.1.0 fixes the issue.
History

Mon, 09 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 20:45:00 +0000

Type Values Removed Values Added
Description Kafbat UI is a web user interface for managing Apache Kafka clusters. An unsafe deserialization vulnerability in version 1.0.0 allows any unauthenticated user to execute arbitrary code on the server. Version 1.1.0 fixes the issue.
Title Kafbat UI vulnerable to Remote Code Execution by JMX in Metrices Configuration
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-06T20:23:25.120Z

Updated: 2025-06-09T15:14:41.161Z

Reserved: 2025-06-02T10:39:41.632Z

Link: CVE-2025-49127

cve-icon Vulnrichment

Updated: 2025-06-09T15:14:23.548Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-06T21:15:23.137

Modified: 2025-06-09T16:15:44.833

Link: CVE-2025-49127

cve-icon Redhat

No data.