Improper authorization in Apache Pulsar - CVE-2024-29834
Published: April 4, 2024
Vulnerability details
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to improper authorization for namespace and topic management endpoints. A remote authenticated user with produce or consume permissions can perform unauthorized operations on partitioned topics, such as unloading topics, triggering compaction, create subscriptions and update subscription properties on partitioned topics.
Affected software
IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library
How to mitigate CVE-2024-29834
IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library - update to 40.0