VendorsApachepulsarall versions
Vulnerabilities

Apache Software Foundation Pulsar

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2024-27317
Apache Pulsar: Pulsar Functions Worker's Archive Extraction Vulnerability Allows Unauthorized File Modification
Published 2024-03-12 · Analyzed
9.9EPSS 0.569
CVE-2024-27135
Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution
Published 2024-03-12 · Modified
9.9EPSS 0.060
CVE-2021-22160
Authentication with JWT allows use of “none”-algorithm
Published 2021-05-26 · Modified
9.8EPSS 0.529
CVE-2023-30429
Apache Pulsar: Incorrect Authorization for Function Worker when using mTLS Authentication through Pulsar Proxy
Published 2023-07-12 · Modified
9.6EPSS 0.010
CVE-2024-27894
Apache Pulsar: Pulsar Functions Worker Allows Unauthorized File Access and Unauthorized HTTP/HTTPS Proxying
Published 2024-03-12 · Analyzed
8.8EPSS 0.019
CVE-2022-34321
Apache Pulsar: Improper Authentication for Pulsar Proxy Statistics Endpoint
Published 2024-03-12 · Analyzed
8.2EPSS 0.018
CVE-2023-30428
Apache Pulsar Broker: Incorrect Authorization Validation for Rest Producer
Published 2023-07-12 · Modified
8.2EPSS 0.008
CVE-2023-37579
Apache Pulsar Function Worker: Incorrect Authorization for Function Worker Can Leak Sink/Source Credentials
Published 2023-07-12 · Modified
8.2EPSS 0.008
CVE-2022-33684
Apache Pulsar C++/Python OAuth Clients prior to 3.0.0 were vulnerable to an MITM attack due to Disabled Certificate Validation
Published 2022-11-04 · Modified
8.1EPSS 0.007
CVE-2023-37544
Apache Pulsar WebSocket Proxy: Improper Authentication for WebSocket Proxy Endpoint Allows DoS
Published 2023-12-20 · Modified
7.5EPSS 0.014
CVE-2023-51437
Apache Pulsar: Timing attack in SASL token signature verification
Published 2024-02-07 · Modified
7.4EPSS 0.008
CVE-2021-41571
Pulsar Admin API allows access to data from other tenants using getMessageById API
Published 2022-02-01 · Modified
6.5EPSS 0.017
CVE-2022-24280
Apache Pulsar Proxy target broker address isn't validated
Published 2022-09-23 · Modified
6.5EPSS 0.014
CVE-2023-31007
Apache Pulsar: Broker does not always disconnect client when authentication data expires
Published 2023-07-12 · Modified
6.5EPSS 0.010
CVE-2025-30677
Apache Pulsar IO Kafka Connector, Apache Pulsar IO Kafka Connect Adaptor: Sensitive information logged in Pulsar's Apache Kafka Connectors
Published 2025-04-09 · Analyzed
6.5EPSS 0.007
CVE-2024-28098
Apache Pulsar: Improper Authorization For Topic-Level Policy Management
Published 2024-03-12 · Modified
6.4EPSS 0.017
CVE-2024-29834
Apache Pulsar: Improper Authorization For Namespace and Topic Management Endpoints
Published 2024-04-02 · Analyzed
6.4EPSS 0.014
CVE-2022-33682
Disabled Hostname Verification makes Brokers, Proxies vulnerable to MITM attack
Published 2022-09-23 · Modified
5.9EPSS 0.007
CVE-2022-33681
Improper Hostname Verification in Java Client and Proxy can expose authentication data via MITM
Published 2022-09-23 · Modified
5.9EPSS 0.007
CVE-2022-33683
Disabled Certificate Validation makes Broker, Proxy Admin Clients vulnerable to MITM attack
Published 2022-09-23 · Modified
5.9EPSS 0.007