Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:41281
HistoryJul 14, 2023 - 6:07 a.m.

Incorrect Authorization

2023-07-1406:07:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
incorrect authorization
vulnerability
authentication
rest producer
topic settings
message exfiltration

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

EPSS

0.001

Percentile

31.3%

org.apache.pulsar:pulsar-broker is vulnerable to Incorrect Authorization. An authenticated users is able to send messages to any topic utilizing the broker’s admin role by using the library’s Rest producer. There are two risks for the impacted users: an attacker might send useless messages to any cluster topic and change topic settings, which might cause messages for other tenants to be exfiltrated or deleted.

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

EPSS

0.001

Percentile

31.3%