CVE-2022-24280 – org.apache.pulsar:pulsar
Package
Manager: maven
Name: org.apache.pulsar:pulsar
Vulnerable Version: >=0 <2.7.5 || >=2.8.0 <2.8.3 || >=2.9.0 <2.9.2
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00026 pctl0.05686
Details
Proxy component of Apache Pulsar subject to abuse as Denial of Service endpoint Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from the Pulsar Proxy's IP address. When the Apache Pulsar Proxy component is used, it is possible to attempt to open TCP/IP connections to any IP address and port that the Pulsar Proxy can connect to. An attacker could use this as a way for DoS attacks that originate from the Pulsar Proxy's IP address. It hasn’t been detected that the Pulsar Proxy authentication can be bypassed. The attacker will have to have a valid token to a properly secured Pulsar Proxy. This issue affects Apache Pulsar Proxy versions 2.7.0 to 2.7.4; 2.8.0 to 2.8.2; 2.9.0 to 2.9.1; 2.6.4 and earlier.
Metadata
Created: 2022-09-25T00:00:18Z
Modified: 2022-09-28T03:28:50Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-3mg9-m3f6-v7fq/GHSA-3mg9-m3f6-v7fq.json
CWE IDs: ["CWE-20"]
Alternative ID: GHSA-3mg9-m3f6-v7fq
Finding: F184
Auto approve: 1