GHSA-rcqj-3fmp-5cqx · Severity: medium · Ecosystem: maven — Apache Pulsar Kafka Connector Logs Sensitive Information in Application Logs
Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka Connect Adaptor Sink Connector log sensitive configuration properties in plain text in application logs. This vulnerability can lead to unintended exposure of credentials in log files, potentially allowing attackers with access to these logs to obtain Apache Kafka credentials. The vulnerability's impact is limited by the fact that an attacker would need access to the application logs to exploit this issue. This issue affects Apache Pulsar IO's Apache Kafka connectors in all versions before 3.0.11, 3.3.6, and 4.0.4. 3.0.x version users should upgrade to at least 3.0.11. 3.3.x version users should upgrade to at least 3.3.6. 4.0.x version users should upgrade to at least 4.0.4. Users operating versions prior to those listed above should upgrade to the aforementioned patched versions or newer versions.
Conclusion & alert: CVE-2025-30677 is rated Moderate Risk (40.5/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.57%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.15% | 0.57% | +0.42% |
| 2 | 2026-05-20 | 0.12% | 0.15% | +0.03% |
| 3 | 2026-05-18 | — | 0.12% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.3 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
GHSA-rcqj-3fmp-5cqx · Severity: medium · Ecosystem: maven — Apache Pulsar Kafka Connector Logs Sensitive Information in Application Logs
| URL | Tags |
|---|---|
| https://lists.apache.org/thread/zv5fwwrh374r1p5cmksxcd40ssxxko3d | Mailing List Vendor Advisory |
| https://pulsar.apache.org/security/ | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/04/09/2 | Mailing List Third Party Advisory |