CVE-2024-27894
Apache Pulsar Function Worker: functions created from a URL allow file access and HTTP proxying
Technology
Apache Pulsar
CVSS Score
8.8 / 10.0
Affected Versions
2.4.0 to 2.10.5; 2.11.0 to 2.11.3; 3.0.0 to 3.0.2; 3.1.0 to 3.1.2; 3.2.0
Upstream Fix
2.10.6; 2.11.4; 3.0.3; 3.1.3; 3.2.1
Published
March 12, 2024
OSSeva Coverage
Fixed upstream
Description
The Function Worker lets authenticated users create functions whose implementation is fetched from a file, http or https URL. This can be used to read files on the worker and to make it fetch arbitrary URLs. Fixed releases restrict URL-based creation by default, with additionalEnabledConnectorUrlPatterns and additionalEnabledFunctionsUrlPatterns to allow specific patterns. Apache scores it 8.5 as the CNA.
Is your Apache Pulsar deployment affected?
If you're running 2.4.0 to 2.10.5; 2.11.0 to 2.11.3; 3.0.0 to 3.0.2; 3.1.0 to 3.1.2; 3.2.0, you need this patch. Book a discovery call to get covered.