Improper authorization in Apache Pulsar - CVE-2024-29834

 

Improper authorization in Apache Pulsar - CVE-2024-29834

Published: April 4, 2024


Vulnerability identifier: #VU88111
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-29834
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges within the application.

The vulnerability exists due to improper authorization for namespace and topic management endpoints. A remote authenticated user with produce or consume permissions can perform unauthorized operations on partitioned topics, such as unloading topics, triggering compaction, create subscriptions and update subscription properties on partitioned topics.


Affected software

Apache Pulsar
IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library

How to mitigate CVE-2024-29834

Install updates from vendor's website.

Apache Pulsar - addressed in versions 3.0.4, 3.2.2
IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library - update to 40.0

External References

Related Security Bulletins