Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://github.com/redpanda-data/redpanda/pull/14969 | patch issue tracking |
https://github.com/redpanda-data/redpanda/pull/15060 | patch issue tracking |
https://github.com/redpanda-data/redpanda/issues/15048 | issue tracking exploit |
https://github.com/redpanda-data/redpanda/compare/v23.1.20...v23.1.21 | release notes |
https://github.com/redpanda-data/redpanda/compare/v23.2.17...v23.2.18 | release notes |