cbcvebase.
CVE-2023-51437
published 2024-02-07

CVE-2023-51437: Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will pass…

PriorityP349high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.76%
51.3th percentile
Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will pass signature verification. Users are recommended to upgrade to version 2.11.3, 3.0.2, or 3.1.1 which fixes the issue. Users should also consider updating the configured secret in the `saslJaasServerRoleTokenSignerSecretPath` file. Any component matching an above version running the SASL Authentication Provider is affected. That includes the Pulsar Broker, Proxy, Websocket Proxy, or Function Worker. 2.11 Pulsar users should upgrade to at least 2.11.3. 3.0 Pulsar users should upgrade to at least 3.0.2. 3.1 Pulsar users should upgrade to at least 3.1.1. Any users running Pulsar 2.8, 2.9, 2.10, and earlier should upgrade to one of the above patched versions. For additional details on this attack vector, please refer to https://codahale.com/a-lesson-in-timing-attacks/ .

Affected

8 ranges
VendorProductVersion rangeFixed in
apachepulsar<= 2.10.5
apachepulsar
apachepulsar>= 2.11.0 < 2.11.32.11.3
apachepulsar>= 3.0.0 < 3.0.23.0.2
apache_software_foundationapache_pulsar<= 2.10.5
apache_software_foundationapache_pulsar
apache_software_foundationapache_pulsar2.11.0 – 2.11.2
apache_software_foundationapache_pulsar3.0.0 – 3.0.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.