google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
860 stars 178 forks source link

PRP: Exposed Kafka UI #510

Open joernNNN opened 1 week ago

joernNNN commented 1 week ago

Hi, According to recently published advisories Apache Kafka UI which is popular product according to its GitHub reputation doesn't enable authentication by default and by using the mentioned CVEs and tsunami callback server, the exposed UI can be validated easily.