Back to Vulnerability Directory
HIGHFixed upstream
CVE-2023-30428
Apache Pulsar broker REST producer: custom header lets a user produce to any topic with the broker's admin role
Technology
Apache Pulsar
CVSS Score
8.1 / 10.0
Affected Versions
2.9.0 to 2.9.5; 2.10.0 to 2.10.3; 2.11.0
Upstream Fix
2.10.4; 2.11.1
Published
July 12, 2023
OSSeva Coverage
Fixed upstream
Description
An authenticated user who connects directly to a broker can add a custom HTTP header to a REST producer request and produce to any topic using the broker's admin role, including the topic-level policies topic of other tenants. Pulsar 2.8 and earlier and 3.0 are not affected, and no 2.9 fix was released.
Is your Apache Pulsar deployment affected?
If you're running 2.9.0 to 2.9.5; 2.10.0 to 2.10.3; 2.11.0, you need this patch. Book a discovery call to get covered.