https://seclists.org/oss-sec/2024/q1/214: CVE-2022-34321: Apache Pulsar: Improper Authentication for Pulsar Proxy Statistics Endpoint
Published Mar 12, 2024
·Updated
Affected Software
1 affected component
Apache Pulsar
Frequently Asked Questions
1
What is CVE-2022-34321?
CVE-2022-34321 refers to an improper authentication vulnerability in the Apache Pulsar Proxy Statistics Endpoint.
2
What is the severity of CVE-2022-34321?
CVE-2022-34321 is rated as a high severity vulnerability due to the potential unauthorized access to sensitive statistics.
3
How do I fix CVE-2022-34321?
To fix CVE-2022-34321, upgrade to the latest version of Apache Pulsar where the vulnerability is addressed.
4
Who is affected by CVE-2022-34321?
Any users running vulnerable versions of Apache Pulsar with the Proxy Statistics Endpoint exposed are affected by CVE-2022-34321.
5
What are the risks associated with CVE-2022-34321?
The risks associated with CVE-2022-34321 include unauthorized access to monitoring and statistics information that can aid in further attacks.