Back to Vulnerability Directory
HIGHFixed upstream

CVE-2023-51437

Apache Pulsar SASL authentication: timing side channel allows forged role tokens

Technology

Apache Pulsar

CVSS Score

7.4 / 10.0

Affected Versions

through 2.10.5; 2.11.0 to 2.11.2; 3.0.0 to 3.0.1; 3.1.0

Upstream Fix

2.11.3; 3.0.2; 3.1.1

Published

February 7, 2024

OSSeva Coverage

Fixed upstream

Description

An observable timing discrepancy in the SASL authentication provider can let an attacker forge a SASL role token that passes signature verification. Brokers, proxies, WebSocket proxies and Function Workers that use the SASL provider are affected. The advisory names no 2.10 or earlier fix and also recommends rotating the secret in the saslJaasServerRoleTokenSignerSecretPath file.

Upstream record: NVD · CVE.org

Is your Apache Pulsar deployment affected?

If you're running through 2.10.5; 2.11.0 to 2.11.2; 3.0.0 to 3.0.1; 3.1.0, you need this patch. Book a discovery call to get covered.