Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2021-22160

Apache Pulsar: JWT authentication accepts tokens signed with the none algorithm

Technology

Apache Pulsar

CVSS Score

9.8 / 10.0

Affected Versions

before 2.7.1

Upstream Fix

2.7.1

Published

May 26, 2021

OSSeva Coverage

Fixed upstream

Description

When Pulsar authenticates clients with JSON Web Tokens, the token signature is not validated if the token's algorithm is set to none, so an attacker can connect as any user, including administrators.

Upstream record: NVD · CVE.org

Is your Apache Pulsar deployment affected?

If you're running before 2.7.1, you need this patch. Book a discovery call to get covered.