GHSA-j3qw-g67q-7m64

    Dashboard / Vulnerabilities / GHSA-j3qw-g67q-7m64

    GHSA-j3qw-g67q-7m64

    Published: 25 Sept 2022Last Modified: 8 Nov 2023

    Summary: Apache Pulsar Brokers and Proxies vulnerable to Improper Certificate Validation

    Details: Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, even when tlsAllowInsecureConnection is disabled via configuration. The Pulsar Admin Client's intra-cluster and geo-replication HTTPS connections are vulnerable to man in the middle attacks, which could leak authentication data, configuration data, and any other data sent by these clients. An attacker can only take advantage of this vulnerability by taking control of a machine 'between' the client and the server. The attacker must then actively manipulate traffic to perform the attack. This issue affects Apache Pulsar Broker and Proxy versions 2.7.0 to 2.7.4; 2.8.0 to 2.8.3; 2.9.0 to 2.9.2; 2.10.0; 2.6.4 and earlier.

    Affected packages

    Package

    Name: org.apache.pulsar:pulsar-broker

    Purl: pkg:maven/org.apache.pulsar/pulsar-broker

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.7.5

    Affected versions

    1.19.0-incubating

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-j3qw-g67q-7m64 | CVE-DB