The Log4j vulnerability has taken the Internet by storm since its discovery late last week. We at Kloudle have been busy keeping up with the different announcements and advisories from Cloud platforms and SaaS providers and creating easy to consume reading and sharing material for your teams and customers. There is constant and ongoing investigations for a host of software being conducted to identify the scope and extent of the vulnerability.
As part of aiding a customer with identifying all vulnerable software, the Platform Security Team at Kloudle undertook an analysis of the Kafka connectors in use to see if they are vulnerable to CVE-2021-44228 and CVE-2021-45046.
Confluent released an advisory to address the prevalence of this vulnerability in Kafka and other products. However, information about whether Kafka connectors are vulnerable or not was not made available when this exercise was undertaken. This analysis was conducted to identify if the Confluent Kafka Connectors in use by our customer are vulnerable or not independently of the updates provided by Confluent.
We analysed the following Kafka Connectors for the log4j vulnerability. None of them were found to be vulnerable.
There are over several hundred Kafka connectors and a lot of them are not Confluent-supported.Confluent has released a notification of the impact to Confluent supported connectors that it was able to identify and is requesting information about any third party connectors if found vulnerable. Our team will continue to identify and report any vulnerable connectors we do discover. Please check back for updates.
We have also added an issue to the CISA Gov Github page regarding our findings.