Back to Vulnerability Directory
HIGHFixed upstream

CVE-2023-30429

Apache Pulsar Function Worker: proxy role used for authorization when the proxy authenticates with mTLS

Technology

Apache Pulsar

CVSS Score

8.8 / 10.0

Affected Versions

before 2.10.4; 2.11.0

Upstream Fix

2.10.4; 2.11.1

Published

July 12, 2023

OSSeva Coverage

Fixed upstream

Description

When a client reaches the Pulsar Function Worker through a Pulsar Proxy that authenticates to the worker with mTLS, the worker authorizes the request with the proxy's role instead of the client's. Pulsar 3.0 is not affected. Apache scores it 9.6 as the CNA.

Upstream record: NVD · CVE.org

Is your Apache Pulsar deployment affected?

If you're running before 2.10.4; 2.11.0, you need this patch. Book a discovery call to get covered.