Apache / Pulsar
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-30677 | Apache Pulsar IO Kafka Connector, Apache Pulsar IO Kafka Connect Adaptor: Sensitive information logged in Pulsar's Apache Kafka Connectors | MEDIUM | 6.3 | Apr 9, 2025 |
| CVE-2024-29834 | Apache Pulsar: Improper Authorization For Namespace and Topic Management Endpoints | HIGH | 8.1 | Apr 2, 2024 |
| CVE-2024-27894 | Apache Pulsar: Pulsar Functions Worker Allows Unauthorized File Access and Unauthorized HTTP/HTTPS Proxying | HIGH | 8.8 | Mar 12, 2024 |
| CVE-2024-27317 | Apache Pulsar: Pulsar Functions Worker's Archive Extraction Vulnerability Allows Unauthorized File Modification | CRITICAL | 9.9 | Mar 12, 2024 |
| CVE-2024-27135 | Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution | CRITICAL | 9.9 | Mar 12, 2024 |
| CVE-2022-34321 | Apache Pulsar: Improper Authentication for Pulsar Proxy Statistics Endpoint | HIGH | 8.2 | Mar 12, 2024 |
| CVE-2024-28098 | Apache Pulsar: Improper Authorization For Topic-Level Policy Management | MEDIUM | 6.4 | Mar 12, 2024 |
| CVE-2023-51437 | Apache Pulsar: Timing attack in SASL token signature verification | HIGH | 7.4 | Feb 7, 2024 |
| CVE-2023-37544 | Apache Pulsar WebSocket Proxy: Improper Authentication for WebSocket Proxy Endpoint Allows DoS | HIGH | 7.5 | Dec 20, 2023 |
| CVE-2023-30428 | Apache Pulsar Broker: Incorrect Authorization Validation for Rest Producer | HIGH | 8.2 | Jul 12, 2023 |
| CVE-2023-30429 | Apache Pulsar: Incorrect Authorization for Function Worker when using mTLS Authentication through Pulsar Proxy | CRITICAL | 9.6 | Jul 12, 2023 |
| CVE-2023-31007 | Apache Pulsar: Broker does not always disconnect client when authentication data expires | MEDIUM | 6.5 | Jul 12, 2023 |
| CVE-2023-37579 | Apache Pulsar Function Worker: Incorrect Authorization for Function Worker Can Leak Sink/Source Credentials | HIGH | 8.2 | Jul 12, 2023 |
| CVE-2022-33684 | Apache Pulsar C++/Python OAuth Clients prior to 3.0.0 were vulnerable to an MITM attack due to Disabled Certificate Validation | HIGH | 8.1 | Nov 4, 2022 |
| CVE-2022-33683 | Disabled Certificate Validation makes Broker, Proxy Admin Clients vulnerable to MITM attack | MEDIUM | 5.9 | Sep 23, 2022 |
| CVE-2022-33682 | Disabled Hostname Verification makes Brokers, Proxies vulnerable to MITM attack | MEDIUM | 5.9 | Sep 23, 2022 |
| CVE-2022-33681 | Improper Hostname Verification in Java Client and Proxy can expose authentication data via MITM | MEDIUM | 5.9 | Sep 23, 2022 |
| CVE-2022-24280 | Apache Pulsar Proxy target broker address isn't validated | MEDIUM | 6.5 | Sep 23, 2022 |
| CVE-2021-41571 | Pulsar Admin API allows access to data from other tenants using getMessageById API | MEDIUM | 6.5 | Feb 1, 2022 |
| CVE-2021-22160 | Authentication with JWT allows use of “none”-algorithm | CRITICAL | 9.8 | May 26, 2021 |
Showing 1 to 20 of 20 CVEs