Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-29834

Apache Pulsar: produce or consume permission allows partitioned topic management operations

Technology

Apache Pulsar

CVSS Score

6.4 / 10.0

Affected Versions

2.7.1 to 2.10.6; 2.11.0 to 2.11.4; 3.0.0 to 3.0.3; 3.1.0 to 3.1.3; 3.2.0 to 3.2.1

Upstream Fix

3.0.4; 3.2.2

Published

April 2, 2024

OSSeva Coverage

Fixed upstream

Description

Authenticated users with produce or consume permission can perform management operations on partitioned topics, such as unloading topics and triggering compaction, and a user with produce permission can create subscriptions and update subscription properties. These should need the tenant admin or superuser role. The advisory sends 3.1 users to 3.2.2 and names no 2.10 or 2.11 fix.

Upstream record: NVD · CVE.org

Is your Apache Pulsar deployment affected?

If you're running 2.7.1 to 2.10.6; 2.11.0 to 2.11.4; 3.0.0 to 3.0.3; 3.1.0 to 3.1.3; 3.2.0 to 3.2.1, you need this patch. Book a discovery call to get covered.