Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2021-22160
Apache Pulsar: JWT authentication accepts tokens signed with the none algorithm
Technology
Apache Pulsar
CVSS Score
9.8 / 10.0
Affected Versions
before 2.7.1
Upstream Fix
2.7.1
Published
May 26, 2021
OSSeva Coverage
Fixed upstream
Is your Apache Pulsar deployment affected?
If you're running before 2.7.1, you need this patch. Book a discovery call to get covered.