Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 02 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aiven-open
Aiven-open klaw |
|
| Vendors & Products |
Aiven-open
Aiven-open klaw |
Tue, 02 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists in the user registration and login mechanisms due to inconsistent handling of username case sensitivity, leading to a targeted Denial of Service (DoS) and complete account lockout. This issue has been patched in version 2.10.4. | |
| Title | Klaw: user lockout due to case sensitivity inconsistency | |
| Weaknesses | CWE-178 CWE-20 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T15:55:58.686Z
Reserved: 2026-05-05T20:15:20.631Z
Link: CVE-2026-44367
Updated: 2026-06-02T15:55:55.507Z
Status : Deferred
Published: 2026-06-02T16:16:41.043
Modified: 2026-06-02T17:15:44.040
Link: CVE-2026-44367
No data.
OpenCVE Enrichment
Updated: 2026-06-02T16:30:13Z