Vulnerability Description
If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none". This allows an attacker to connect to Pulsar instances as any user (incl. admins).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Pulsar | < 2.7.1 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/r347650d15a3e9c5f58b83e918b6ad6dedc2a63d3ebMailing ListVendor Advisory
- https://lists.apache.org/thread.html/r8e545559781231a83bf0644548c660255859e52feb
- https://lists.apache.org/thread.html/r9a12b4da2f26ce9b8f7e7117a879efaa973dab7e54Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/ra49cb62105154e4795b259c79a6b27d63bfa2ab578
- https://lists.apache.org/thread.html/ra49cb62105154e4795b259c79a6b27d63bfa2ab578
- https://lists.apache.org/thread.html/rbe845aa1573a61769b9c5916c62971f4b10de87c2e
- https://lists.apache.org/thread.html/rca54f4b26ba5e6f2e39732b47ec51640e89f57e3b6
- https://lists.apache.org/thread.html/rf2e90942996dceebac8296abf39257cfeb5ae918f8
- https://lists.apache.org/thread.html/r347650d15a3e9c5f58b83e918b6ad6dedc2a63d3ebMailing ListVendor Advisory
- https://lists.apache.org/thread.html/r8e545559781231a83bf0644548c660255859e52feb
- https://lists.apache.org/thread.html/r9a12b4da2f26ce9b8f7e7117a879efaa973dab7e54Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/ra49cb62105154e4795b259c79a6b27d63bfa2ab578
- https://lists.apache.org/thread.html/ra49cb62105154e4795b259c79a6b27d63bfa2ab578
- https://lists.apache.org/thread.html/rbe845aa1573a61769b9c5916c62971f4b10de87c2e
- https://lists.apache.org/thread.html/rca54f4b26ba5e6f2e39732b47ec51640e89f57e3b6
FAQ
What is CVE-2021-22160?
CVE-2021-22160 is a vulnerability with a CVSS score of 9.8 (CRITICAL). If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none"...
How severe is CVE-2021-22160?
CVE-2021-22160 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-22160?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Pulsar.