Arbitrary Java Code Execution Vulnerability in Pulsar Function Worker
CVE-2024-27135
9.9CRITICAL
What is CVE-2024-27135?
The vulnerability in the Apache Pulsar Function Worker stems from improper input validation, which allows an authenticated malicious user to execute arbitrary Java code outside the intended sandboxes for user-provided functions. This issue can extend to the Pulsar Broker when the 'functionsWorkerEnabled' configuration is set to true, thus impacting a broader range of deployments. Users operating the affected versions are urged to upgrade to the specified patched versions to mitigate potential risks.
Affected Version(s)
Apache Pulsar 2.4.0 < 2.10.6
Apache Pulsar 2.11.0 < 2.11.4
Apache Pulsar 3.0.0 < 3.0.3