CVE-2025-49127

Source
https://cve.org/CVERecord?id=CVE-2025-49127
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49127.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-49127
Aliases
  • GHSA-g3mf-c374-fgh2
Published
2025-06-06T20:23:25Z
Modified
2026-08-12T03:51:22Z
Severity
  • 8.9 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Kafbat UI vulnerable to Remote Code Execution by JMX in Metrices Configuration
Details

Kafbat UI is a web user interface for managing Apache Kafka clusters. An unsafe deserialization vulnerability in version 1.0.0 allows any unauthenticated user to execute arbitrary code on the server. Version 1.1.0 fixes the issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-502"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49127.json"
}
References

Affected packages

Git / github.com/kafbat/kafka-ui

Affected ranges

Type
GIT
Repo
https://github.com/kafbat/kafka-ui
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "= 1.0.0"
        },
        {
            "last_affected": "= 1.0.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

= 1.*
= 1.0.0
v1.*
v1.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49127.json"