[ 
https://issues.apache.org/jira/browse/KAFKA-20815?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Ken Huang updated KAFKA-20815:
------------------------------
    Fix Version/s:     (was: 4.3.2)

> Security : [jline-remote-telnet] [3.30.4] 
> ------------------------------------------
>
>                 Key: KAFKA-20815
>                 URL: https://issues.apache.org/jira/browse/KAFKA-20815
>             Project: Kafka
>          Issue Type: Bug
>    Affects Versions: 4.3.0
>            Reporter: Krishna Chidrawar
>            Assignee: Gergely Harmadás
>            Priority: Critical
>              Labels: security
>             Fix For: 4.4.0
>
>
> h2. GHSA-47qp-hqvx-6r3f : 
> The JLine3 Telnet server (`remote-telnet` module) does not limit the number of
> environment variables a client may inject via the Telnet NEW-ENVIRON option. 
> An
> unauthenticated attacker can flood the server with a large number of unique
> variable pairs before sending the terminating IAC SE byte, exhausting JVM heap
> *URL :* [https://github.com/advisories/GHSA-47qp-hqvx-6r3f]
> *Fix Version :* 4.2.1
> h2. GHSA-2r2c-cx56-8933: 
> The JLine3 Telnet server (`remote-telnet` module) does not apply an upper 
> bound to
> terminal dimensions received via the Telnet NAWS (Negotiate About Window 
> Size) option.
> An unauthenticated remote attacker can send a NAWS subnegotiation advertising 
> a
> 65535×65535 terminal and repeatedly alternate values to trigger continuous, 
> expensive
> *URL :* [https://github.com/advisories/GHSA-2r2c-cx56-8933]
> *Fix Version :* 4.2.1



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to