Back to Vulnerability Directory
HIGHFixed upstream

CVE-2024-27894

Apache Pulsar Function Worker: functions created from a URL allow file access and HTTP proxying

Technology

Apache Pulsar

CVSS Score

8.8 / 10.0

Affected Versions

2.4.0 to 2.10.5; 2.11.0 to 2.11.3; 3.0.0 to 3.0.2; 3.1.0 to 3.1.2; 3.2.0

Upstream Fix

2.10.6; 2.11.4; 3.0.3; 3.1.3; 3.2.1

Published

March 12, 2024

OSSeva Coverage

Fixed upstream

Description

The Function Worker lets authenticated users create functions whose implementation is fetched from a file, http or https URL. This can be used to read files on the worker and to make it fetch arbitrary URLs. Fixed releases restrict URL-based creation by default, with additionalEnabledConnectorUrlPatterns and additionalEnabledFunctionsUrlPatterns to allow specific patterns. Apache scores it 8.5 as the CNA.

Upstream record: NVD · CVE.org

Is your Apache Pulsar deployment affected?

If you're running 2.4.0 to 2.10.5; 2.11.0 to 2.11.3; 3.0.0 to 3.0.2; 3.1.0 to 3.1.2; 3.2.0, you need this patch. Book a discovery call to get covered.