#VU87558 Missing Authorization in Apache Pulsar - CVE-2022-34321
Published: March 15, 2024 / Updated: March 15, 2024
Apache Pulsar
Apache Foundation
Description
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to missing authorization at the "/proxy-stats" endpoint. A remote non-authenticated attacker can use the endpoint to view detailed statistics about live connections and modify the logging level of proxied connections.