QID 982355
QID 982355: Java (maven) Security Update for org.apache.pulsar:pulsar (GHSA-3cv4-xxv7-934q)
If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none". This allows an attacker to connect to Pulsar instances as any user (incl. admins).
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3cv4-xxv7-934q for updates pertaining to this vulnerability.
Vendor References
- GHSA-3cv4-xxv7-934q -
github.com/advisories/GHSA-3cv4-xxv7-934q
CVEs related to QID 982355
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3cv4-xxv7-934q | org.apache.pulsar:pulsar |
|