CVE-2023-25194 is an unsafe deserialization vulnerability in Apache Kafka Connect's handling of connector Kafka-client SASL JAAS configurations. An authenticated operator who can create or modify connectors can configure a connector client's SASL JAAS setting to use JndiLoginModule through producer, consumer, or admin override properties. Kafka Connect can then contact an attacker-controlled LDAP service and deserialize its response. This permits unrestricted deserialization of untrusted data and can enable Java deserialization gadget-chain execution on the Kafka Connect server when suitable gadget classes are present on its classpath.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains a single Metasploit module that exploits CVE-2023-25194, a JNDI injection vulnerability in Apache Druid's /druid/indexer/v1/sampler HTTP endpoint. The exploit targets Druid instances using vulnerable Kafka clients (versions 2.3.0 to 3.3.2) and leverages the ability to inject a malicious sasl.jaas.config property, causing the server to connect to an attacker-controlled LDAP server. The module sets up a local LDAP server to deliver a serialized Java payload, which can result in remote code execution on the target. The exploit supports both Windows and Linux targets and can deliver customizable payloads, such as reverse shells or Meterpreter sessions. The code is written in Ruby and is structured as a standard Metasploit exploit module, with clear separation of initialization, vulnerability checking, payload delivery, and exploitation logic.
This repository contains a Go-based exploit for CVE-2023-25194, a deserialization vulnerability in Apache Druid's Kafka ingestion. The exploit is operational and automates the entire attack chain: it sets up both a malicious LDAP server (for JNDI injection) and an HTTP server (to serve a Java class payload), then crafts and sends a specially crafted HTTP request to the vulnerable Druid endpoint. If the target is vulnerable, the exploit results in remote code execution, providing the attacker with a reverse shell. The main exploit logic is in 'cve-2023-25194.go', which handles target validation, version checking, infrastructure setup, and payload delivery. The repository is well-structured for ease of use, with a Makefile and Dockerfile for building and running the exploit, and a README with usage instructions and example output. The exploit targets Apache Druid versions prior to 26.0.0 running on Linux, and requires the attacker to specify their own infrastructure for the LDAP and HTTP servers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Confluent-related JNDI/JndiLoginModule issue referenced only to distinguish it from the attack chain described in the content.
A CVE referenced by the advisory without vulnerability details in the provided content.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.