cbcvebase.
CVE-2024-27135
published 2024-03-12

CVE-2024-27135: Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker…

PriorityP273critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
5.98%
92.5th percentile
Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions. This vulnerability also applies to the Pulsar Broker when it is configured with "functionsWorkerEnabled=true". This issue affects Apache Pulsar versions from 2.4.0 to 2.10.5, from 2.11.0 to 2.11.3, from 3.0.0 to 3.0.2, from 3.1.0 to 3.1.2, and 3.2.0. 2.10 Pulsar Function Worker users should upgrade to at least 2.10.6. 2.11 Pulsar Function Worker users should upgrade to at least 2.11.4. 3.0 Pulsar Function Worker users should upgrade to at least 3.0.3. 3.1 Pulsar Function Worker users should upgrade to at least 3.1.3. 3.2 Pulsar Function Worker users should upgrade to at least 3.2.1. Users operating versions prior to those listed above should upgrade to the aforementioned patched versions or newer versions.

Affected

10 ranges
VendorProductVersion rangeFixed in
apachepulsar
apachepulsar>= 2.11.0 < 2.11.42.11.4
apachepulsar>= 2.4.0 < 2.10.62.10.6
apachepulsar>= 3.0.0 < 3.0.33.0.3
apachepulsar>= 3.1.0 < 3.1.33.1.3
apache_software_foundationapache_pulsar>= 2.11.0 < 2.11.42.11.4
apache_software_foundationapache_pulsar>= 2.4.0 < 2.10.62.10.6
apache_software_foundationapache_pulsar>= 3.0.0 < 3.0.33.0.3
apache_software_foundationapache_pulsar>= 3.1.0 < 3.1.33.1.3
apache_software_foundationapache_pulsar>= 3.2.0 < 3.2.13.2.1

Detection & IOCsextracted from sources · hover to see the quote

  • Detect exploitation attempts targeting the Pulsar Function Worker RCE vulnerability by monitoring for authenticated requests that submit malicious Java code outside of designated sandboxes on the Function Worker API endpoint.
  • Monitor Pulsar Broker instances configured with 'functionsWorkerEnabled=true' for anomalous Java code execution activity, as they share the same attack surface as the Function Worker.
  • Flag Apache Pulsar deployments running versions 2.4.0–2.10.5, 2.11.0–2.11.3, 3.0.0–3.0.2, 3.1.0–3.1.2, or 3.2.0 as vulnerable and prioritize for patching or enhanced monitoring.
  • ·The Pulsar Broker is only vulnerable when explicitly configured with the 'functionsWorkerEnabled=true' flag; deployments without this flag are not exposed to this attack vector.
  • ·Exploitation requires the attacker to be an authenticated user; unauthenticated access alone is insufficient to trigger the vulnerability.
  • ·No mitigation short of patching is available per Red Hat Product Security assessment; detection and upgrade are the primary response actions.

CVSS provenance

nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_redhat8.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.