CVE-2022-24280

Improper Input Validation in maven/org.apache.pulsar/pulsar-broker-common

Identifiers

CVE-2022-24280

Package Slug

maven/org.apache.pulsar/pulsar-broker-common

Vulnerability

Improper Input Validation

Description

Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from the Pulsar Proxy's IP address. When the Apache Pulsar Proxy component is used, it is possible to attempt to open TCP/IP connections to any IP address and port that the Pulsar Proxy can connect to. An attacker could use this as a way for DoS attacks that originate from the Pulsar Proxy's IP address. It hasn’t been detected that the Pulsar Proxy authentication can be bypassed. The attacker will have to have a valid token to a properly secured Pulsar Proxy. This issue affects Apache Pulsar Proxy versions 2.7.0 to 2.7.4; 2.8.0 to 2.8.2; 2.9.0 to 2.9.1; 2.6.4 and earlier.

Affected Versions

All versions up to 2.6.4, all versions starting from 2.7.0 before 2.7.5, all versions starting from 2.8.0 before 2.8.3, all versions starting from 2.9.0 before 2.9.2

Solution

Upgrade to versions 2.7.5, 2.8.3, 2.9.2 or above.

Last Modified

2022-09-27

source