CVE-2023-37544

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
20/12/2023
Last modified:
04/01/2024

Description

Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication.<br /> <br /> This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 through 2.9.*, from 2.10.0 through 2.10.4, from 2.11.0 through 2.11.1, 3.0.0.<br /> <br /> The known risks include a denial of service due to the WebSocket Proxy accepting any connections, and excessive data transfer due to misuse of the WebSocket ping/pong feature.<br /> <br /> 2.10 Pulsar WebSocket Proxy users should upgrade to at least 2.10.5.<br /> 2.11 Pulsar WebSocket Proxy users should upgrade to at least 2.11.2.<br /> 3.0 Pulsar WebSocket Proxy users should upgrade to at least 3.0.1.<br /> 3.1 Pulsar WebSocket Proxy users are unaffected.<br /> Any users running the Pulsar WebSocket Proxy for 2.8, 2.9, and earlier should upgrade to one of the above patched versions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:pulsar:*:*:*:*:*:*:*:* 2.10.5 (excluding)
cpe:2.3:a:apache:pulsar:*:*:*:*:*:*:*:* 2.11.0 (including) 2.11.2 (excluding)
cpe:2.3:a:apache:pulsar:3.0.0:*:*:*:*:*:*:*