CVE-2024-27135: Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution
Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions. This vulnerability also applies to the Pulsar Broker when it is configured with "functionsWorkerEnabled=true".
This issue affects Apache Pulsar versions from 2.4.0 to 2.10.5, from 2.11.0 to 2.11.3, from 3.0.0 to 3.0.2, from 3.1.0 to 3.1.2, and 3.2.0.
2.10 Pulsar Function Worker users should upgrade to at least 2.10.6. 2.11 Pulsar Function Worker users should upgrade to at least 2.11.4. 3.0 Pulsar Function Worker users should upgrade to at least 3.0.3. 3.1 Pulsar Function Worker users should upgrade to at least 3.1.3. 3.2 Pulsar Function Worker users should upgrade to at least 3.2.1.
Users operating versions prior to those listed above should upgrade to the aforementioned patched versions or newer versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27135?
CVE-2024-27135 has been classified with a high severity due to its potential to allow arbitrary code execution by an authenticated user.
How do I fix CVE-2024-27135?
To fix CVE-2024-27135, upgrade the Pulsar Functions Worker to versions 3.2.1, 3.1.3, 3.0.3, 2.11.4, or 2.10.6 depending on your current version.
Who is affected by CVE-2024-27135?
CVE-2024-27135 affects users of Apache Pulsar, specifically those utilizing affected versions of the Pulsar Functions Worker.
What impact does CVE-2024-27135 have on my system?
CVE-2024-27135 can allow a malicious authenticated user to execute arbitrary Java code, potentially compromising the integrity of the Pulsar Function worker.
Is there a workaround for CVE-2024-27135?
There are no recommended workarounds for CVE-2024-27135; upgrading to a patched version is necessary to mitigate the vulnerability.