216.73.216.233

CVE-2025-61673

· Published 03/10/2025 22:15 · Modified 03/10/2025 22:15

Labels: CVE-2025-61673 2025-10-03CVE-2025-61673CWE-288[email protected]

Essential information

Published
03/10/2025 22:15
Modified
03/10/2025 22:15
Author
Creator
CVSS
8.6 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

CVSS metrics

Description

Karapace is an open-source implementation of Kafka REST and Schema Registry. Versions 5.0.0 and 5.0.1 contain an authentication bypass vulnerability when configured to use OAuth 2.0 Bearer Token authentication. If a request is sent without an Authorization header, the token validation logic is skipped entirely, allowing an unauthenticated user to read and write to Schema Registry endpoints that should otherwise be protected. This effectively renders the OAuth authentication mechanism ineffective. This issue is fixed in version 5.0.2.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
karapace / karapace cpe:2.3:a:karapace:karapace:5.0.0:*:*:*:*:*:*:*
karapace / karapace cpe:2.3:a:karapace:karapace:5.0.1:*:*:*:*:*:*:*

References