PT-2024-3207 · Apache · Apache Pulsar

·

CVE-2023-51437

·

Published

2024-02-07

·

Updated

2024-07-22

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Pulsar versions prior to 2.11.3 Apache Pulsar versions prior to 3.0.2 Apache Pulsar versions prior to 3.1.1
Description The issue is related to an observable timing discrepancy vulnerability in the Apache Pulsar SASL Authentication Provider, which can allow an attacker to forge a SASL Role Token that will pass signature verification. This vulnerability may impact the confidentiality and integrity of protected information.
Recommendations For Apache Pulsar version 2.11, upgrade to at least version 2.11.3. For Apache Pulsar version 3.0, upgrade to at least version 3.0.2. For Apache Pulsar version 3.1, upgrade to at least version 3.1.1. For any versions prior to 2.11.3, 3.0.2, or 3.1.1, consider upgrading to one of the above patched versions and update the configured secret in the saslJaasServerRoleTokenSignerSecretPath file.

Exploit

Fix

Side Channel Attack

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03433
CVE-2023-51437
GHSA-C57V-4VG5-CM2X

Affected Products

Apache Pulsar