Back to Vulnerability Directory
HIGHFixed upstream

CVE-2023-30428

Apache Pulsar broker REST producer: custom header lets a user produce to any topic with the broker's admin role

Technology

Apache Pulsar

CVSS Score

8.1 / 10.0

Affected Versions

2.9.0 to 2.9.5; 2.10.0 to 2.10.3; 2.11.0

Upstream Fix

2.10.4; 2.11.1

Published

July 12, 2023

OSSeva Coverage

Fixed upstream

Description

An authenticated user who connects directly to a broker can add a custom HTTP header to a REST producer request and produce to any topic using the broker's admin role, including the topic-level policies topic of other tenants. Pulsar 2.8 and earlier and 3.0 are not affected, and no 2.9 fix was released.

Upstream record: NVD · CVE.org

Is your Apache Pulsar deployment affected?

If you're running 2.9.0 to 2.9.5; 2.10.0 to 2.10.3; 2.11.0, you need this patch. Book a discovery call to get covered.