Apache Pulsar Function Worker: Incorrect Authorization for Function Worker Can Leak Sink/Source Credentials
CVE-2023-37579
8.2HIGH
What is CVE-2023-37579?
An Incorrect Authorization vulnerability exists in Apache Pulsar's Function Worker, allowing authenticated users to access configuration data for sources and sinks without proper authorization. Many of these configurations may contain sensitive credentials, leading to potential credential leaks. Although the exposure risk is somewhat mitigated as users cannot enumerate another tenant's sources or sinks, relying on guesswork to identify vulnerable configurations still poses a significant risk. To safeguard against this issue, users are strongly advised to upgrade to the latest patched versions of the Function Worker.
Affected Version(s)
Apache Pulsar Function Worker 0 < 2.10.4
Apache Pulsar Function Worker 2.11.0