If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none". This allows an attacker to connect to Pulsar instances as any user (incl. admins).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2021-05-26T12:22:31
Updated: 2024-08-03T18:37:18.090Z
Reserved: 2021-01-05T00:00:00
Link: CVE-2021-22160
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-05-26T13:15:07.697
Modified: 2024-11-21T05:49:37.470
Link: CVE-2021-22160
Redhat
No data.