Executive brief
Klaw, a self-service portal for managing Apache Kafka data streams, contained a security flaw that could allow unauthorized individuals to view password hashes. If an attacker obtains these hashes, they could attempt to crack them to gain unauthorized access to the system, potentially compromising data governance and management operations. The issue has been resolved in the latest software update by removing the unnecessary component that leaked this information.
Technical details
An improper access control vulnerability (CWE-284/CWE-200) exists in Aiven-Open Klaw prior to version 2.10.4. The flaw resides in an undocumented or unused API endpoint that fails to properly restrict access, allowing unauthenticated remote attackers to retrieve password hashes. While the hashes themselves are not plaintext passwords, they can be subjected to offline brute-force or dictionary attacks to recover user credentials. The vulnerability was remediated in version 2.10.4 by completely removing the affected endpoint from both the frontend and backend codebases.
Affected products
- Aiven-Open Klaw < 2.10.4
Timeline
- 2026-05-12: advisory: GitHub Security Advisory published
- 2026-05-13: patched: Version 2.10.4 released
- 2026-06-02: disclosed: CVE-2026-45080 published to NVD