CVE-2024-29834
Apache Pulsar: produce or consume permission allows partitioned topic management operations
Technology
Apache Pulsar
CVSS Score
6.4 / 10.0
Affected Versions
2.7.1 to 2.10.6; 2.11.0 to 2.11.4; 3.0.0 to 3.0.3; 3.1.0 to 3.1.3; 3.2.0 to 3.2.1
Upstream Fix
3.0.4; 3.2.2
Published
April 2, 2024
OSSeva Coverage
Fixed upstream
Description
Authenticated users with produce or consume permission can perform management operations on partitioned topics, such as unloading topics and triggering compaction, and a user with produce permission can create subscriptions and update subscription properties. These should need the tenant admin or superuser role. The advisory sends 3.1 users to 3.2.2 and names no 2.10 or 2.11 fix.
Is your Apache Pulsar deployment affected?
If you're running 2.7.1 to 2.10.6; 2.11.0 to 2.11.4; 3.0.0 to 3.0.3; 3.1.0 to 3.1.3; 3.2.0 to 3.2.1, you need this patch. Book a discovery call to get covered.