CVE-2024-27135
published 2024-03-12CVE-2024-27135: Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker…
PriorityP273critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
5.98%
92.5th percentile
Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions. This vulnerability also applies to the Pulsar Broker when it is configured with "functionsWorkerEnabled=true".
This issue affects Apache Pulsar versions from 2.4.0 to 2.10.5, from 2.11.0 to 2.11.3, from 3.0.0 to 3.0.2, from 3.1.0 to 3.1.2, and 3.2.0.
2.10 Pulsar Function Worker users should upgrade to at least 2.10.6.
2.11 Pulsar Function Worker users should upgrade to at least 2.11.4.
3.0 Pulsar Function Worker users should upgrade to at least 3.0.3.
3.1 Pulsar Function Worker users should upgrade to at least 3.1.3.
3.2 Pulsar Function Worker users should upgrade to at least 3.2.1.
Users operating versions prior to those listed above should upgrade to the aforementioned patched versions or newer versions.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | pulsar | — | — |
| apache | pulsar | >= 2.11.0 < 2.11.4 | 2.11.4 |
| apache | pulsar | >= 2.4.0 < 2.10.6 | 2.10.6 |
| apache | pulsar | >= 3.0.0 < 3.0.3 | 3.0.3 |
| apache | pulsar | >= 3.1.0 < 3.1.3 | 3.1.3 |
| apache_software_foundation | apache_pulsar | >= 2.11.0 < 2.11.4 | 2.11.4 |
| apache_software_foundation | apache_pulsar | >= 2.4.0 < 2.10.6 | 2.10.6 |
| apache_software_foundation | apache_pulsar | >= 3.0.0 < 3.0.3 | 3.0.3 |
| apache_software_foundation | apache_pulsar | >= 3.1.0 < 3.1.3 | 3.1.3 |
| apache_software_foundation | apache_pulsar | >= 3.2.0 < 3.2.1 | 3.2.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts targeting the Pulsar Function Worker RCE vulnerability by monitoring for authenticated requests that submit malicious Java code outside of designated sandboxes on the Function Worker API endpoint. ↗
- →Monitor Pulsar Broker instances configured with 'functionsWorkerEnabled=true' for anomalous Java code execution activity, as they share the same attack surface as the Function Worker. ↗
- →Flag Apache Pulsar deployments running versions 2.4.0–2.10.5, 2.11.0–2.11.3, 3.0.0–3.0.2, 3.1.0–3.1.2, or 3.2.0 as vulnerable and prioritize for patching or enhanced monitoring. ↗
- ·The Pulsar Broker is only vulnerable when explicitly configured with the 'functionsWorkerEnabled=true' flag; deployments without this flag are not exposed to this attack vector. ↗
- ·Exploitation requires the attacker to be an authenticated user; unauthenticated access alone is insufficient to trigger the vulnerability. ↗
- ·No mitigation short of patching is available per Red Hat Product Security assessment; detection and upgrade are the primary response actions. ↗
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_redhat8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution
osv·2024-03-12
CVE-2024-27135 [HIGH] Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution
Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution
Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions. This vulnerability also applies to the Pulsar Broker when it is configured with "functionsWorkerEnabled=true".
This issue affects Apache Pulsar versions from 2.4.0 to 2.10.5, from 2.11.0 to 2.11.3, from 3.0.0 to 3.0.2, from 3.1.0 to 3.1.2, and 3.2.0.
2.10 Pulsar Function Worker users should upgrade to at least 2.10.6.
2.11 Pulsar Function Worker users should upgrade to at least 2.11.4.
3.0 Pulsar Function Worker users should upgrade to at least 3.0.3.
3.1 Pulsar Funct
GHSA
Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution
ghsa·2024-03-12
CVE-2024-27135 [HIGH] CWE-20 Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution
Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution
Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions. This vulnerability also applies to the Pulsar Broker when it is configured with "functionsWorkerEnabled=true".
This issue affects Apache Pulsar versions from 2.4.0 to 2.10.5, from 2.11.0 to 2.11.3, from 3.0.0 to 3.0.2, from 3.1.0 to 3.1.2, and 3.2.0.
2.10 Pulsar Function Worker users should upgrade to at least 2.10.6.
2.11 Pulsar Function Worker users should upgrade to at least 2.11.4.
3.0 Pulsar Function Worker users should upgrade to at least 3.0.3.
3.1 Pulsar Funct
Red Hat
apache-pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution
vendor_redhat·2024-03-12·CVSS 8.5
CVE-2024-27135 [HIGH] CWE-20 apache-pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution
apache-pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution
Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions. This vulnerability also applies to the Pulsar Broker when it is configured with "functionsWorkerEnabled=true".
This issue affects Apache Pulsar versions from 2.4.0 to 2.10.5, from 2.11.0 to 2.11.3, from 3.0.0 to 3.0.2, from 3.1.0 to 3.1.2, and 3.2.0.
2.10 Pulsar Function Worker users should upgrade to at least 2.10.6.
2.11 Pulsar Function Worker users should upgrade to at least 2.11.4.
3.0 Pulsar Function Worker users should upgrade to at least 3.0.3.
3.1 Pulsar Functio
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2024/03/12/9https://lists.apache.org/thread/dh8nj2vmb2br6thjltq74lk9jxkz62wnhttps://pulsar.apache.org/security/CVE-2024-27135/http://www.openwall.com/lists/oss-security/2024/03/12/9https://lists.apache.org/thread/dh8nj2vmb2br6thjltq74lk9jxkz62wnhttps://pulsar.apache.org/security/CVE-2024-27135/
2024-03-12
Published