Apache.Pulsar.JSON.Web.Token.Authentication.Bypass

description-logoDescription

This indicates an attack attempt to exploit an Authentication Bypass Vulnerability in Apache Software Foundation Pulsar.
The vulnerability is due to improper handling of unsigned JSON Web Tokens. An unauthenticated, remote attacker can exploit this vulnerability by sending a request with an unsigned JSON Web Token to a target server with JWT authentication enabled. Successful exploitation results in the attacker bypassing authentication and gaining the ability to interact with the affected service, potentially with administrative privileges.

affected-products-logoAffected Products

Apache Software Foundation Pulsar prior to 2.7.1

Impact logoImpact

Privilege Escalation: Remote attackers can leverage their privileges on vulnerable systems.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2021-06-28 18.105 Default_action:pass:drop
2021-06-15 18.098