conduktor.io ↗

KIP-1188 — New ConnectorClientConfigOverridePolicy with allowlist of configurations

Accepted Kafka 4.2 Connect

Introduces a new built-in ConnectorClientConfigOverridePolicy named AllowlistConnectorClientConfigOverridePolicy with a configurable connector.client.config.override.policy.allowlist that restricts connector config overrides to an explicit set. Multiple CVEs (including RCE via SASL JAAS JndiLoginModule) exploited the default All policy; the None policy is too restrictive while the Principal policy proved unsafe.

Details

AuthorMickael Maison
StatusAccepted
Kafka Version4.2
JIRAKAFKA-19824
WikiView on Apache Wiki
Created2025-06-20
Last Modified2025-10-24
Explore how this KIP affects the Kafka protocol in the Protocol Explorer, or see the full KIP database.