Skip to main content

Vendor/product archive

apache / pulsar CVEs

Beta · best-effort

20 CVEs tagged to apache / pulsar2 Critical, 9 High, 8 Medium, 0 Low, 1 Unrated.

CVE-2025-30677

Published Apr 9, 2025

Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka Connect Adaptor Sink Connector…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-29834

Published Apr 2, 2024

This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28098

Published Mar 12, 2024

The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings. These manage…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27894

Published Mar 12, 2024

The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported UR…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27317

Published Mar 12, 2024

In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Functions Worker. However, if a…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27135

Published Mar 12, 2024

Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxe…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34321

Published Mar 12, 2024

Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes det…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51437

Published Feb 7, 2024

Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will pass signature verification. U…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37544

Published Dec 20, 2023

Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication. This issue affects Apache P…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37579

Published Jul 12, 2023

Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. Any authenticated…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31007

Published Jul 12, 2023

Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authentication data expires if the cli…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2023-30429

Published Jul 12, 2023

Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. When a client connects to the Pul…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-30428

Published Jul 12, 2023

Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenticated user with a custom HTTP header to produce a message t…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33684

Published Nov 4, 2022

The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllowInsecureConnection is disable…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33683

Published Sep 23, 2022

Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, even when tlsAllowInsecureConnection is disabled via configura…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33682

Published Sep 23, 2022

TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, the Pulsar WebSocket Proxy's Java Client, and the Pulsar Pro…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33681

Published Sep 23, 2022

Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in the middle attack. Connections from the Pulsar Java Client…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24280

Published Sep 23, 2022

Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from the Pulsar Proxy's IP address…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41571

Published Feb 1, 2022

In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API get-message-by-id requires th…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22160

Published May 26, 2021

If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1