rapid7 / metasploit-framework

Metasploit Framework
https://www.metasploit.com/
Other
33.76k stars 13.89k forks source link

Apache Kafka UI RCEs #19341

Open h00die opened 1 month ago

h00die commented 1 month ago

Summary

3 new RCEs in Apache Kafka UI

Basic example

https://github.blog/security/vulnerability-research/3-ways-to-get-remote-code-execution-in-kafka-ui/

Motivation

RCE is king

gardnerapp commented 1 month ago

Just a heads up there is already an exploit for the first vulnerability in the post