PT-2023-22685 · Apache · Apache Pulsar Broker

Michael Marshall

·

Publicado

2023-07-12

·

Atualizado

2023-07-20

·

CVE-2023-30428

CVSS v3.1

8.2

Alta

VetorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Pulsar Broker versions 2.9.0 through 2.9.5 Apache Pulsar Broker versions 2.10.0 through 2.10.3 Apache Pulsar Broker version 2.11.0
Description The issue is related to an Incorrect Authorization vulnerability in Apache Pulsar Broker's Rest Producer, allowing an authenticated user with a custom HTTP header to produce a message to any topic using the broker's admin role. This can be exploited when an attacker connects directly to the Pulsar Broker. The vulnerability poses two known risks: producing garbage messages to any topic in the cluster and influencing topic settings for other tenants, potentially leading to exfiltration and/or deletion of messages.
Recommendations Apache Pulsar Broker versions 2.9.0 through 2.9.5 should upgrade to one of the patched versions. Apache Pulsar Broker versions 2.10.0 through 2.10.3 should upgrade to at least version 2.10.4. Apache Pulsar Broker version 2.11.0 should upgrade to at least version 2.11.1.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-30428
GHSA-J2R7-3RVW-G7GX

Produtos afetados

Apache Pulsar Broker