CVE-2022-24280
published 2022-09-23CVE-2022-24280: Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from the…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.25%
66.2th percentile
Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from the Pulsar Proxy's IP address. When the Apache Pulsar Proxy component is used, it is possible to attempt to open TCP/IP connections to any IP address and port that the Pulsar Proxy can connect to. An attacker could use this as a way for DoS attacks that originate from the Pulsar Proxy's IP address. It hasn’t been detected that the Pulsar Proxy authentication can be bypassed. The attacker will have to have a valid token to a properly secured Pulsar Proxy. This issue affects Apache Pulsar Proxy versions 2.7.0 to 2.7.4; 2.8.0 to 2.8.2; 2.9.0 to 2.9.1; 2.6.4 and earlier.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | pulsar | <= 2.6.4 | — |
| apache | pulsar | >= 2.7.0 < 2.7.5 | 2.7.5 |
| apache | pulsar | >= 2.8.0 < 2.8.3 | 2.8.3 |
| apache | pulsar | >= 2.9.0 < 2.9.2 | 2.9.2 |
| apache_software_foundation | apache_pulsar | 2.6 and earlier – 2.6.4 | — |
| apache_software_foundation | apache_pulsar | 2.7 – 2.7.4 | — |
| apache_software_foundation | apache_pulsar | 2.8 – 2.8.2 | — |
| apache_software_foundation | apache_pulsar | 2.9 – 2.9.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Proxy component of Apache Pulsar subject to abuse as Denial of Service endpoint
osv·2022-09-25
CVE-2022-24280 [MEDIUM] Proxy component of Apache Pulsar subject to abuse as Denial of Service endpoint
Proxy component of Apache Pulsar subject to abuse as Denial of Service endpoint
Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from the Pulsar Proxy's IP address. When the Apache Pulsar Proxy component is used, it is possible to attempt to open TCP/IP connections to any IP address and port that the Pulsar Proxy can connect to. An attacker could use this as a way for DoS attacks that originate from the Pulsar Proxy's IP address. It hasn’t been detected that the Pulsar Proxy authentication can be bypassed. The attacker will have to have a valid token to a properly secured Pulsar Proxy. This issue affects Apache Pulsar Proxy versions 2.7.0 to 2.7.4; 2.8.0 to 2.8.2; 2.9.0 to 2.9.1; 2.6.4 and earl
GHSA
Proxy component of Apache Pulsar subject to abuse as Denial of Service endpoint
ghsa·2022-09-25
CVE-2022-24280 [MEDIUM] CWE-20 Proxy component of Apache Pulsar subject to abuse as Denial of Service endpoint
Proxy component of Apache Pulsar subject to abuse as Denial of Service endpoint
Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from the Pulsar Proxy's IP address. When the Apache Pulsar Proxy component is used, it is possible to attempt to open TCP/IP connections to any IP address and port that the Pulsar Proxy can connect to. An attacker could use this as a way for DoS attacks that originate from the Pulsar Proxy's IP address. It hasn’t been detected that the Pulsar Proxy authentication can be bypassed. The attacker will have to have a valid token to a properly secured Pulsar Proxy. This issue affects Apache Pulsar Proxy versions 2.7.0 to 2.7.4; 2.8.0 to 2.8.2; 2.9.0 to 2.9.1; 2.6.4 and earl
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-23
Published