id: unauth-apache-kafka-ui info: name: Apache Kafka - Unauthorized UI Exposure author: theamanrawat severity: medium description: Unauthorized access to apache kakfa UI. reference: - https://www.acunetix.com/vulnerabilities/web/apache-kafka-unauthorized-access-vulnerability - https://github.com/provectus/kafka-ui classification: cpe: cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:* metadata: verified: true max-request: 2 vendor: apache product: kafka shodan-query: http.title:"UI for Apache Kafka" tags: misconfig,apache,kafka,unauth,exposure http: - method: GET path: - '{{BaseURL}}' - '{{BaseURL}}/ui/clusters/kafka-ui/brokers' stop-at-first-match: true matchers-condition: and matchers: - type: word part: body words: - 'UI for Apache Kafka' - type: status status: - 200 # digest: 490a0046304402206dc7661e71e13acc62d018addc835358ef65e810a2e9bbfb63ec620570a91fb40220099ee2861417d99fb781d6b7bbf052a89d73f4e01834a0c466374a568a178513:922c64590222798bb761d5b6d8e72950