Aiven Google BigQuery Kafka Connect Sink Connector Arbitrary File Read Vulnerability

Vulnerability

An arbitrary file read vulnerability has been identified in Aiven's Google BigQuery Kafka Connect Sink connector, prior to version 2.11.0. The vulnerability arises because the connector does not validate externally-sourced Google Cloud credential configurations before they are processed by Google authentication libraries. This lack of validation allows an attacker to supply a malicious credential configuration with crafted file paths or URL endpoints, leading to unauthorized file reads or Server-Side Request Forgery (SSRF) attacks.

Impact

Exploitation of this vulnerability could result in unrestricted read access to the file system. Additionally, in a standalone Kafka Connect instance, the service keys could be used to impersonate the Kafka broker.

Reproduction

To reproduce this vulnerability, upload a credential JSON file containing malicious paths or URLs as the 'credential_source.file' or 'credential_source.url' endpoints. The connector will process these credentials without validation, allowing for arbitrary file reads or SSRF attacks.

Remediation

Users are advised to upgrade to version 2.11.0 or later.

Added: Jan 16, 2026, 5:21 PM
Updated: Jan 16, 2026, 5:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.8
exploitability
5.8
remediation
0.0
relevance
2.0
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.