<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apache Pulsar (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/apache-pulsar.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/apache-pulsar-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apache Pulsar (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:06 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2024-27894 – The Pulsar Functions Worker includes a capability that permits authenticated use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27894</guid>
    <pubDate>Tue, 12 Mar 2024 19:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27894</strong></p>
  <p>The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported URL schemes include "file", "http", and "https". When a function is created using this method, the Functions Worker will retrieve the implementation from the URL provided by the user. However, this feature introduces a vul…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27317 – In Pulsar Functions Worker, authenticated users can upload functions in jar or n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27317</guid>
    <pubDate>Tue, 12 Mar 2024 19:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27317</strong></p>
  <p>In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Functions Worker. However, if a malicious file is uploaded, it could exploit a directory traversal vulnerability. This occurs when the filenames in the zip files, which aren't properly validated, contain special elements like "..", altering the directo…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27135 – Improper input validation in the Pulsar Function Worker allows a malicious authe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27135</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27135</guid>
    <pubDate>Tue, 12 Mar 2024 19:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27135</strong></p>
  <p>Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions. This vulnerability also applies to the Pulsar Broker when it is configured with "functionsWorkerEnabled=true".  This issue affects Apache Pulsar versions from 2.4.0 to 2.…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27135">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34321 – Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34321</guid>
    <pubDate>Tue, 12 Mar 2024 19:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34321</strong></p>
  <p>Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes detailed statistics about live connections, along with the capability to modify the logging level of proxied connections without requiring proper authentication credentials.  This issue affects Apache Pulsar versions from 2…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51437 – Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51437</guid>
    <pubDate>Wed, 07 Feb 2024 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51437</strong></p>
  <p>Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will pass signature verification. Users are recommended to upgrade to version 2.11.3, 3.0.2, or 3.1.1 which fixes the issue. Users should also consider updating the configured secret in the `saslJaasServerRoleTokenSignerSecretPath` file.  Any component ma…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37544 – Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37544</guid>
    <pubDate>Wed, 20 Dec 2023 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37544</strong></p>
  <p>Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication.  This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 through 2.9.*, from 2.10.0 through 2.10.4, from 2.11.0 through 2.11.1, 3.0.0.  The known risks include a denial of service due to the WebSocket Proxy accepting…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37579 – Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37579</guid>
    <pubDate>Wed, 12 Jul 2023 10:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37579</strong></p>
  <p>Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker.  This issue affects Apache Pulsar: before 2.10.4, and 2.11.0.  Any authenticated user can retrieve a source's configuration or a sink's configuration without authorization. Many sources and sinks contain credentials in the configuration, which could lead to leaked credentials. This vulnerability is…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-30429 – Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30429</guid>
    <pubDate>Wed, 12 Jul 2023 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-30429</strong></p>
  <p>Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar.  This issue affects Apache Pulsar: before 2.10.4, and 2.11.0.  When a client connects to the Pulsar Function Worker via the Pulsar Proxy where the Pulsar Proxy uses mTLS authentication to authenticate with the Pulsar Function Worker, the Pulsar Function Worker incorrectly performs authorization by using the Proxy's…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30428 – Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30428</guid>
    <pubDate>Wed, 12 Jul 2023 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30428</strong></p>
  <p>Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenticated user with a custom HTTP header to produce a message to any topic using the broker's admin role. This issue affects Apache Pulsar Brokers: from 2.9.0 through 2.9.5, from 2.10.0 before 2.10.4, 2.11.0.  The vulnerability is exploitable when an attacker can connect directly to…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-33684 – The Apache Pulsar C++ Client does not verify peer TLS certificates when making H...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-33684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-33684</guid>
    <pubDate>Fri, 04 Nov 2022 12:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-33684</strong></p>
  <p>The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllowInsecureConnection is disabled via configuration. This vulnerability allows an attacker to perform a man in the middle attack and intercept and/or modify the GET request that is sent to the ClientCredentialFlow 'issuer url'. The intercepted credenti…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33684">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-22160 – If Apache Pulsar is configured to authenticate clients using tokens based on JSO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22160</guid>
    <pubDate>Wed, 26 May 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-22160</strong></p>
  <p>If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none". This allows an attacker to connect to Pulsar instances as any user (incl. admins).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22160">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
