Back to Vulnerability Directory
HIGHFixed upstream

CVE-2022-34321

Apache Pulsar Proxy: /proxy-stats endpoint needs no authentication

Technology

Apache Pulsar

CVSS Score

8.2 / 10.0

Affected Versions

2.6.0 to 2.10.5; 2.11.0 to 2.11.2; 3.0.0 to 3.0.1; 3.1.0

Upstream Fix

2.10.6; 2.11.3; 3.0.2; 3.1.1

Published

March 12, 2024

OSSeva Coverage

Fixed upstream

Description

The Pulsar Proxy's /proxy-stats endpoint can be reached without authentication. It exposes detailed statistics about live connections and can change the logging level of proxied connections. The advisory adds that the proxy is not designed to be exposed directly to the internet.

Upstream record: NVD · CVE.org

Is your Apache Pulsar deployment affected?

If you're running 2.6.0 to 2.10.5; 2.11.0 to 2.11.2; 3.0.0 to 3.0.1; 3.1.0, you need this patch. Book a discovery call to get covered.