Apache Pulsar WebSocket Proxy: Improper Authentication for WebSocket Proxy Endpoint Allows DoS
CVE-2023-37544

7.5HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
20 December 2023

Summary

The Apache Pulsar WebSocket Proxy is affected by an improper authentication vulnerability that permits unauthorized access to the /pingpong endpoint. This flaw enables attackers to connect without proper credentials, leading to potential denial of service conditions due to unrestricted connection acceptance. Additionally, this vulnerability could result in excessive data transfer, exploiting the WebSocket ping/pong functionality. Users of versions 2.8.x, 2.9.x, and earlier must upgrade to the patched versions of 2.10.5, 2.11.2, or 3.0.1 to mitigate associated risks.

Affected Version(s)

Apache Pulsar WebSocket Proxy 2.8.0 <= 2.8.*

Apache Pulsar WebSocket Proxy 2.9.0 <= 2.9.*

Apache Pulsar WebSocket Proxy 2.10.0 <= 2.10.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Marshall of DataStax
.