Access of Resource Using Incompatible Type ('Type Confusion') Affecting redpanda-data/redpanda package, versions [,22.2.11)[22.3.0,22.3.14)[23.1.0,23.1.2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.59% (44th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-REDPANDADATAREDPANDA-5416672
  • published9 Apr 2023
  • disclosed9 Apr 2023
  • creditUnknown

Introduced: 9 Apr 2023

CVE-2023-30450  (opens in a new tab)
CWE-843  (opens in a new tab)

How to fix?

Upgrade redpanda-data/redpanda to version 22.2.11, 22.3.14, 23.1.2 or higher.

Overview

Affected versions of this package are vulnerable to Access of Resource Using Incompatible Type ('Type Confusion') due to mishandling the redpanda.rpc_server_tls field, leading to situations in which there is a data type mismatch that cannot be automatically fixed by rpk, and instead a user must reconfigure (while a cluster is turned off) in order to have TLS on broker RPC ports.

CVSS Base Scores

version 3.1