CVE-2023-3281Medium

CVE-2023-3281 Cortex XSOAR: Cleartext Exposure of Client Certificate Key in Kafka v3 Integration

Published
October 11, 2023
Last Modified
October 11, 2023

🔗 CVE IDs covered (1)

CVE-2023-3281 · pending

📋 Description

A problem with the Cortex XSOAR Kafka v3 integration can result in the cleartext exposure of the configured Kafka client certificate key.

🎯 Affected products1

  • Cortex XSOAR Kafka Integration

✅ Remediation

This issue is fixed in the Cortex XSOAR Kafka v3 integration in version 2.0.16 and all later versions of the integration. A new Kafka client certificate key should be used by the Kafka v3 integration after you upgrade it to a fixed version. You should also revoke the existing Kafka client certificate key to prevent the misuse of a previously exposed secret key.

🔗 References (1)