CVE-2024-27317
Apache Pulsar Function Worker: archive extraction lets an uploaded jar or nar write outside its directory
Technology
Apache Pulsar
CVSS Score
9.9 / 10.0
Affected Versions
2.4.0 to 2.10.5; 2.11.0 to 2.11.3; 3.0.0 to 3.0.2; 3.1.0 to 3.1.2; 3.2.0
Upstream Fix
2.10.6; 2.11.4; 3.0.3; 3.1.3; 3.2.1
Published
March 12, 2024
OSSeva Coverage
Fixed upstream
Description
Authenticated users can upload functions as jar or nar files, which the Function Worker extracts without validating entry names. A crafted archive with path traversal elements can write files outside the extraction directory. Brokers with functionsWorkerEnabled=true are affected too. Apache scores it 8.4 as the CNA.
Is your Apache Pulsar deployment affected?
If you're running 2.4.0 to 2.10.5; 2.11.0 to 2.11.3; 3.0.0 to 3.0.2; 3.1.0 to 3.1.2; 3.2.0, you need this patch. Book a discovery call to get covered.