GHSA-7mg2-6c6v-342r

    Dashboard / Vulnerabilities / GHSA-7mg2-6c6v-342r

    GHSA-7mg2-6c6v-342r

    Published: 2 Apr 2024Last Modified: 2 May 2024

    Summary: Apache Pulsar: Improper Authorization For Namespace and Topic Management Endpoints

    Details: This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering compaction. These management operations should be restricted to users with the tenant admin role or superuser role. An authenticated user with produce permission can create subscriptions and update subscription properties on partitioned topics, even though this should be limited to users with consume permissions. This impact analysis assumes that Pulsar has been configured with the default authorization provider. For custom authorization providers, the impact could be slightly different. Additionally, the vulnerability allows an authenticated user to read, create, modify, and delete namespace properties in any namespace in any tenant. In Pulsar, namespace properties are reserved for user provided metadata about the namespace. This issue affects Apache Pulsar versions from 2.7.1 to 2.10.6, from 2.11.0 to 2.11.4, from 3.0.0 to 3.0.3, from 3.1.0 to 3.1.3, and from 3.2.0 to 3.2.1. 3.0 Apache Pulsar users should upgrade to at least 3.0.4. 3.1 and 3.2 Apache Pulsar users should upgrade to at least 3.2.2. Users operating versions prior to those listed above should upgrade to the aforementioned patched versions or newer versions.

    Affected packages

    Package

    Name: org.apache.pulsar:pulsar-broker

    Purl: pkg:maven/org.apache.pulsar/pulsar-broker

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 2.7.1
    Fixed -None

    Affected versions

    2.10.0
    2.10.1
    2.10.2
    2.10.3
    2.10.4
    2.10.5
    2.10.6

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-7mg2-6c6v-342r | CVE-DB