CVE-2025-66623 Details
Description
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 and prior to 0.49.1, in some situations, Strimzi creates an incorrect Kubernetes Role which grants the Apache Kafka Connect and Apache Kafka MirrorMaker 2 operands the GET access to all Kubernetes Secrets that exist in the given Kubernetes namespace. The issue is fixed in Strimzi 0.49.1.
A vulnerability in Strimzi Kafka Operator versions 0.47.0 prior to 0.49.1 allows Apache Kafka Connect and MirrorMaker 2 to access all Kubernetes Secrets in their namespace. This issue arises from the creation of an incorrect Kubernetes Role that grants GET permissions on Secrets. The vulnerability is exploitable when Kafka Connect or MirrorMaker 2 is deployed without proper TLS or mTLS configurations, or when certain authentication options are not specified. In such cases, Pods can access Secrets using their Service Account, although they cannot list or modify these Secrets.
Upgrade to Strimzi Kafka Operator version 0.49.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linuxfoundation strimzi | < 0.49.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 25, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 4, 2026 | Initial Analysis | [email protected] |
| Dec 5, 2025 | New CVE Received | [email protected] |