CVE-2019-12399

When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect cluster to obtain the connector's task configuration and the response will contain the plaintext secret rather than the externalized secrets variables.

Published: 2020-01-14 Last update: 2024-11-21 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2019-12399 is rated Moderate Risk (62.7/100): CVSS High severity, with medium exploitation likelihood (EPSS 3.91%). Core evidence: EPSS rose +1.61% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2019-12399

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 2.31% 3.91% +1.61%
2 2025-12-16 1.62% 2.31% +0.69%
3 2025-12-07 1.62%

Full EPSS history (20 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2019-12399

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.5 3.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
3.9 3.6 [email protected]
5.0 2.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
10.0 2.9 [email protected]

Weakness enumeration for CVE-2019-12399

GitHub Security Advisory for CVE-2019-12399

GHSA-6jmf-mxwf-r3jc · Severity: high · Ecosystem: maven — Exposure of Sensitive Information to an Unauthorized Actor in Apache Kafka

OS Trackers for CVE-2019-12399

vendor priority summary link
redhat medium https://access.redhat.com/security/cve/CVE-2019-12399

Affected software / configurations for CVE-2019-12399

Vendor Product Version Raw CPE
apache kafka 2.0.0 cpe:2.3:a:apache:kafka:2.0.0:*:*:*:*:*:*:*
apache kafka 2.0.1 cpe:2.3:a:apache:kafka:2.0.1:*:*:*:*:*:*:*
apache kafka 2.1.0 cpe:2.3:a:apache:kafka:2.1.0:*:*:*:*:*:*:*
apache kafka 2.1.1 cpe:2.3:a:apache:kafka:2.1.1:*:*:*:*:*:*:*
apache kafka 2.2.0 cpe:2.3:a:apache:kafka:2.2.0:*:*:*:*:*:*:*
apache kafka 2.2.1 cpe:2.3:a:apache:kafka:2.2.1:*:*:*:*:*:*:*
apache kafka 2.3.0 cpe:2.3:a:apache:kafka:2.3.0:*:*:*:*:*:*:*
oracle banking_corporate_lending_process_management 14.1.0 cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.1.0:*:*:*:*:*:*:*
oracle banking_corporate_lending_process_management 14.3.0 cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.3.0:*:*:*:*:*:*:*
oracle banking_corporate_lending_process_management 14.4.0 cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.4.0:*:*:*:*:*:*:*
oracle banking_credit_facilities_process_management 14.1.0 cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.1.0:*:*:*:*:*:*:*
oracle banking_credit_facilities_process_management 14.3.0 cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.3.0:*:*:*:*:*:*:*
oracle banking_credit_facilities_process_management 14.4.0 cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.4.0:*:*:*:*:*:*:*
oracle banking_liquidity_management >= 14.0.0, <= 14.4.0 cpe:2.3:a:oracle:banking_liquidity_management:*:*:*:*:*:*:*:*
oracle banking_payments 14.4.0 cpe:2.3:a:oracle:banking_payments:14.4.0:*:*:*:*:*:*:*
oracle banking_platform 2.7.0 cpe:2.3:a:oracle:banking_platform:2.7.0:*:*:*:*:*:*:*
oracle banking_supply_chain_finance >= 14.2.0, <= 14.4.0 cpe:2.3:a:oracle:banking_supply_chain_finance:*:*:*:*:*:*:*:*
oracle banking_trade_finance_process_management 14.1.0 cpe:2.3:a:oracle:banking_trade_finance_process_management:14.1.0:*:*:*:*:*:*:*
oracle banking_trade_finance_process_management 14.3.0 cpe:2.3:a:oracle:banking_trade_finance_process_management:14.3.0:*:*:*:*:*:*:*
oracle banking_trade_finance_process_management 14.4.0 cpe:2.3:a:oracle:banking_trade_finance_process_management:14.4.0:*:*:*:*:*:*:*
oracle banking_virtual_account_management 14.1.0 cpe:2.3:a:oracle:banking_virtual_account_management:14.1.0:*:*:*:*:*:*:*
oracle banking_virtual_account_management 14.3.0 cpe:2.3:a:oracle:banking_virtual_account_management:14.3.0:*:*:*:*:*:*:*
oracle banking_virtual_account_management 14.4.0 cpe:2.3:a:oracle:banking_virtual_account_management:14.4.0:*:*:*:*:*:*:*
oracle blockchain_platform < 21.1.2 cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:*
oracle communications_cloud_native_core_policy 1.9.0 cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.9.0:*:*:*:*:*:*:*
oracle financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.1.0 cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*
oracle flexcube_universal_banking 14.4.0 cpe:2.3:a:oracle:flexcube_universal_banking:14.4.0:*:*:*:*:*:*:*

References for CVE-2019-12399

URL Tags
http://www.openwall.com/lists/oss-security/2020/01/14/1 Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r0e3a613705d70950aca2bfe9a6265c87503921852d9a3dbce512ca9f%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r2d390dec5f360ec8aa294bef18e1a4385e2a3698d747209216f5a48b%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r3154f5adbc905f1f9012a92240c8e00a96628470cc819453b9606d0e%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r3203d7f25a6ca56ff3e48c43a6aa7cb60b8e5d57d0eed9f76dc2b7a8%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r47c225db363d1ee2c18c4b3b2f51b63a9789f78c7fa602e5976ecd05%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r4b20b40c40d4a4c641e2ef4228098a57935e5782bfdfdf3650e48265%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r4d9e87cdae99e98d7b244cfa53d9d2532d368d3a187fbc87c493dcbe%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r56eb055b544931451283fee51f7e1f5b8ebd3085fed7d77aaba504c9%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r6af5ed95726874e9add022955be83c192428c248d1c9a1914aff89d9%40%3Cannounce.apache.org%3E
https://lists.apache.org/thread.html/r6af5ed95726874e9add022955be83c192428c248d1c9a1914aff89d9%40%3Cdev.kafka.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r6af5ed95726874e9add022955be83c192428c248d1c9a1914aff89d9%40%3Cusers.kafka.apache.org%3E
https://lists.apache.org/thread.html/r6fa1cff4786dcef2ddd1d717836ef123c878e8321c24855bad24ae0f%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r801c68bf987931f35d2e24ecc99f3aa2850fdd8f5ef15fe6c60fecf3%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r8890b8f18f1de821595792b58b968a89692a255bc20d86d395270740%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r9871a4215b621c1d09deee5eba97f0f44fde01b4363deb1bed0dd160%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/rc27d424d0bdeaf31081c3e246db3c66e882243ae3f342dfa845e0261%40%3Ccommits.kafka.apache.org%3E
https://lists.apache.org/thread.html/rda253155601968331b5cf0da4f273813bbd91843c2568a8495d1c662%40%3Ccommits.kafka.apache.org%3E
https://lists.apache.org/thread.html/rde947ee866de6687bc51cdc8dfa6d7e6b3ad4ce8c708c344f773e6dc%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/rfe90ca0463c199b99c2921410639aed53a172ea8b733eab0dc776262%40%3Ccommits.druid.apache.org%3E
https://www.oracle.com//security-alerts/cpujul2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html Patch Third Party Advisory
cvelogic Threat Intelligence