Back to Vulnerability Directory
HIGHFixed upstream
CVE-2022-34321
Apache Pulsar Proxy: /proxy-stats endpoint needs no authentication
Technology
Apache Pulsar
CVSS Score
8.2 / 10.0
Affected Versions
2.6.0 to 2.10.5; 2.11.0 to 2.11.2; 3.0.0 to 3.0.1; 3.1.0
Upstream Fix
2.10.6; 2.11.3; 3.0.2; 3.1.1
Published
March 12, 2024
OSSeva Coverage
Fixed upstream
Description
The Pulsar Proxy's /proxy-stats endpoint can be reached without authentication. It exposes detailed statistics about live connections and can change the logging level of proxied connections. The advisory adds that the proxy is not designed to be exposed directly to the internet.
Is your Apache Pulsar deployment affected?
If you're running 2.6.0 to 2.10.5; 2.11.0 to 2.11.2; 3.0.0 to 3.0.1; 3.1.0, you need this patch. Book a discovery call to get covered.