Back to Vulnerability Directory
HIGHFixed upstream

CVE-2023-37544

Apache Pulsar WebSocket Proxy: /pingpong endpoint accepts unauthenticated connections

Technology

Apache Pulsar

CVSS Score

7.5 / 10.0

Affected Versions

2.8.x; 2.9.x; 2.10.0 to 2.10.4; 2.11.0 to 2.11.1; 3.0.0

Upstream Fix

2.10.5; 2.11.2; 3.0.1

Published

December 20, 2023

OSSeva Coverage

Fixed upstream

Description

The Pulsar WebSocket Proxy lets an attacker connect to the /pingpong endpoint without authentication, which can be used for denial of service. Pulsar 3.1 is not affected, and 2.8 and 2.9 users are told to move to a patched release.

Upstream record: NVD · CVE.org

Is your Apache Pulsar deployment affected?

If you're running 2.8.x; 2.9.x; 2.10.0 to 2.10.4; 2.11.0 to 2.11.1; 3.0.0, you need this patch. Book a discovery call to get covered.