CVE-2023-51437
Apache Pulsar SASL authentication: timing side channel allows forged role tokens
Technology
Apache Pulsar
CVSS Score
7.4 / 10.0
Affected Versions
through 2.10.5; 2.11.0 to 2.11.2; 3.0.0 to 3.0.1; 3.1.0
Upstream Fix
2.11.3; 3.0.2; 3.1.1
Published
February 7, 2024
OSSeva Coverage
Fixed upstream
Description
An observable timing discrepancy in the SASL authentication provider can let an attacker forge a SASL role token that passes signature verification. Brokers, proxies, WebSocket proxies and Function Workers that use the SASL provider are affected. The advisory names no 2.10 or earlier fix and also recommends rotating the secret in the saslJaasServerRoleTokenSignerSecretPath file.
Is your Apache Pulsar deployment affected?
If you're running through 2.10.5; 2.11.0 to 2.11.2; 3.0.0 to 3.0.1; 3.1.0, you need this patch. Book a discovery call to get covered.