QID 997708
Date Published: 2024-03-14
QID 997708: Java (Maven) Security Update for org.apache.pulsar:pulsar-proxy (GHSA-c35h-w8hj-mm55)
Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes detailed statistics about live connections, along with the capability to modify the logging level of proxied connections without requiring proper authentication credentials.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-c35h-w8hj-mm55 for updates and patch information.
Vendor References
- GHSA-c35h-w8hj-mm55 -
github.com/advisories/GHSA-c35h-w8hj-mm55
CVEs related to QID 997708
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c35h-w8hj-mm55 | org.apache.pulsar:pulsar-proxy |
|