CVE-2024-28098
published 2024-03-12CVE-2024-28098: The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading…
PriorityP433medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
1.70%
74.6th percentile
The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings. These management operations should be restricted to users with the tenant admin role or super user role.
This issue affects Apache Pulsar versions from 2.7.1 to 2.10.5, from 2.11.0 to 2.11.3, from 3.0.0 to 3.0.2, from 3.1.0 to 3.1.2, and 3.2.0.
2.10 Apache Pulsar users should upgrade to at least 2.10.6.
2.11 Apache Pulsar users should upgrade to at least 2.11.4.
3.0 Apache Pulsar users should upgrade to at least 3.0.3.
3.1 Apache Pulsar users should upgrade to at least 3.1.3.
3.2 Apache Pulsar users should upgrade to at least 3.2.1.
Users operating versions prior to those listed above should upgrade to the aforementioned patched versions or newer versions.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | pulsar | — | — |
| apache | pulsar | >= 2.11.0 < 2.11.4 | 2.11.4 |
| apache | pulsar | >= 2.7.1 < 2.10.6 | 2.10.6 |
| apache | pulsar | >= 3.0.0 < 3.0.3 | 3.0.3 |
| apache | pulsar | >= 3.1.0 < 3.1.3 | 3.1.3 |
| apache_software_foundation | apache_pulsar | >= 2.11.0 < 2.11.4 | 2.11.4 |
| apache_software_foundation | apache_pulsar | >= 2.7.1 < 2.10.6 | 2.10.6 |
| apache_software_foundation | apache_pulsar | >= 3.0.0 < 3.0.3 | 3.0.3 |
| apache_software_foundation | apache_pulsar | >= 3.1.0 < 3.1.3 | 3.1.3 |
| apache_software_foundation | apache_pulsar | >= 3.2.0 < 3.2.1 | 3.2.1 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Pulsar: Improper Authorization For Topic-Level Policy Management
osv·2024-03-12
CVE-2024-28098 [MEDIUM] Apache Pulsar: Improper Authorization For Topic-Level Policy Management
Apache Pulsar: Improper Authorization For Topic-Level Policy Management
The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings. These management operations should be restricted to users with the tenant admin role or super user role.
This issue affects Apache Pulsar versions from 2.7.1 to 2.10.5, from 2.11.0 to 2.11.3, from 3.0.0 to 3.0.2, from 3.1.0 to 3.1.2, and 3.2.0.
2.10 Apache Pulsar users should upgrade to at least 2.10.6.
2.11 Apache Pulsar users should upgrade to at least 2.11.4.
3.0 Apache Pulsar users should upgrade to at least 3.0.3.
3.1 Apache Pulsar users should upgrade to at least 3.1.3.
3.2 Apache Pulsar users should upgrade to at least 3.2.1.
Users operating ve
GHSA
Apache Pulsar: Improper Authorization For Topic-Level Policy Management
ghsa·2024-03-12
CVE-2024-28098 [MEDIUM] CWE-863 Apache Pulsar: Improper Authorization For Topic-Level Policy Management
Apache Pulsar: Improper Authorization For Topic-Level Policy Management
The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings. These management operations should be restricted to users with the tenant admin role or super user role.
This issue affects Apache Pulsar versions from 2.7.1 to 2.10.5, from 2.11.0 to 2.11.3, from 3.0.0 to 3.0.2, from 3.1.0 to 3.1.2, and 3.2.0.
2.10 Apache Pulsar users should upgrade to at least 2.10.6.
2.11 Apache Pulsar users should upgrade to at least 2.11.4.
3.0 Apache Pulsar users should upgrade to at least 3.0.3.
3.1 Apache Pulsar users should upgrade to at least 3.1.3.
3.2 Apache Pulsar users should upgrade to at least 3.2.1.
Users operating ve
Red Hat
apache-pulsar: Improper Authorization For Topic-Level Policy Management
vendor_redhat·2024-03-12·CVSS 6.4
CVE-2024-28098 [MEDIUM] CWE-863 apache-pulsar: Improper Authorization For Topic-Level Policy Management
apache-pulsar: Improper Authorization For Topic-Level Policy Management
The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings. These management operations should be restricted to users with the tenant admin role or super user role.
This issue affects Apache Pulsar versions from 2.7.1 to 2.10.5, from 2.11.0 to 2.11.3, from 3.0.0 to 3.0.2, from 3.1.0 to 3.1.2, and 3.2.0.
2.10 Apache Pulsar users should upgrade to at least 2.10.6.
2.11 Apache Pulsar users should upgrade to at least 2.11.4.
3.0 Apache Pulsar users should upgrade to at least 3.0.3.
3.1 Apache Pulsar users should upgrade to at least 3.1.3.
3.2 Apache Pulsar users should upgrade to at least 3.2.1.
Users operating versi
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2024/03/12/12https://lists.apache.org/thread/3m6923y3wxpdcs9346sjvt8ql9swqc2zhttps://pulsar.apache.org/security/CVE-2024-28098/http://www.openwall.com/lists/oss-security/2024/03/12/12https://lists.apache.org/thread/3m6923y3wxpdcs9346sjvt8ql9swqc2zhttps://pulsar.apache.org/security/CVE-2024-28098/
2024-03-12
Published