Applicability of CVE-2025-27817 to Clarity
search cancel

Applicability of CVE-2025-27817 to Clarity

book

Article ID: 444660

calendar_today

Updated On:

Products

Clarity PPM On Premise Clarity FedRAMP Clarity PPM SaaS

Issue/Introduction

Is Clarity impacted by CVE-2025-27817?

 

Environment

Clarity 16.2.3,16.3.3,16.4.0,16.4.1,16.4.2

Cause

A high-severity security vulnerability CVE-2025-27817 was recently disclosed affecting the Apache Kafka Client, a third-party library used for data messaging. 

Resolution

While the Clarity codebase does contain a version of the library that is flagged by security scanners, the vulnerability cannot be exploited in Clarity. Clarity's internal architecture acts as a strict filter, preventing the specific type of malicious input required to trigger this issue.