PT-2021-3274 · Apache · Apache Pulsar

Michael Marshall

·

Published

2021-05-25

·

Updated

2022-06-04

·

CVE-2021-22160

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Pulsar (affected versions not specified)
Description The issue is related to the authentication mechanism in Apache Pulsar when using JSON Web Tokens (JWT) for client authentication. If the algorithm of the presented token is set to "none", the signature of the token is not validated. This allows an attacker to connect to Pulsar instances as any user, including administrators. The vulnerability is associated with incorrect validation of the cryptographic signature, which can be exploited by a remote attacker to gain unauthorized access to protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03036
CVE-2021-22160
GHSA-3CV4-XXV7-934Q

Affected Products

Apache Pulsar