CVE-2026-96740 StreamsHub Console for Apache Kafka 配置注入漏洞
影响攻击者可窃取 console-api 的 ServiceAccount 令牌
StreamsHub Console for Apache Kafka 存在配置注入缺陷。租户在 Console 自定义资源中提供的 Kafka 客户端属性未经安全敏感键过滤,被直接复制进 console-api 的 AdminClient 配置。拥有 Console CR 编写权限的攻击者可借此将 console-api 的 ServiceAccount 令牌外带到其控制的 broker。
影响范围
StreamsHub Console for Apache Kafka,具体受影响版本范围暂无公开信息。
漏洞详情
漏洞类型为安全配置注入/敏感信息泄露。成因是 Console 自定义资源中的 Kafka 客户端属性在合并到 console-api AdminClient 配置时未过滤 config.providers、bootstrap.servers 等安全敏感键。攻击者可设置 config.providers 加载恶意配置提供者,并把 bootstrap.servers 指向自己控制的 broker,从而在 AdminClient 建立连接时将 ServiceAccount 令牌外泄。
利用条件与风险
利用前提是攻击者具备创建或修改 Console 自定义资源的权限。成功利用后可获取 console-api 的 ServiceAccount 令牌,进而可能访问集群内该服务账号可触达的资源,CVSS 6.5 属中等风险。
修复建议
官方修复方案暂无公开信息,建议关注厂商公告并升级到修复版本。临时缓解措施包括限制可创建/修改 Console CR 的用户范围,并避免为 console-api 的 ServiceAccount 授予过高权限。
A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to exfiltrate the console-api ServiceAccount token to an attacker-controlled broker.