CVE-2023-37544

Published: Dic 20, 2023 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2023-3156 Aliases: GHSA-83q5-whqp-r8jr
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available

Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication.

This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 through 2.9.*, from 2.10.0 through 2.10.4, from 2.11.0 through 2.11.1, 3.0.0.

The known risks include a denial of service due to the WebSocket Proxy accepting any connections, and excessive data transfer due to misuse of the WebSocket ping/pong feature.

2.10 Pulsar WebSocket Proxy users should upgrade to at least 2.10.5.
2.11 Pulsar WebSocket Proxy users should upgrade to at least 2.11.2.
3.0 Pulsar WebSocket Proxy users should upgrade to at least 3.0.1.
3.1 Pulsar WebSocket Proxy users are unaffected.
Any users running the Pulsar WebSocket Proxy for 2.8, 2.9, and earlier should upgrade to one of the above patched versions.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0007
Percentile
0,2th
Updated

EPSS Score Trend (Last 90 Days)

287

Improper Authentication

Draft
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability Access Control
Potential Impacts:
Read Application Data Gain Privileges Or Assume Identity Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies: ICS/OT, Not Technology-Specific, Web Based
View CWE Details
Application

Pulsar by Apache

Version Range Affected
From 2.11.0 (inclusive)
To 2.11.2 (exclusive)
cpe:2.3:a:apache:pulsar:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Pulsar by Apache

cpe:2.3:a:apache:pulsar:3.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Pulsar by Apache

Version Range Affected
To 2.10.5 (exclusive)
cpe:2.3:a:apache:pulsar:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://lists.apache.org/thread/od0k9zts1toc9h9snbqq4pjpyx28mv4m
http://www.openwall.com/lists/oss-security/2023/12/20/2
https://lists.apache.org/thread/od0k9zts1toc9h9snbqq4pjpyx28mv4m
http://www.openwall.com/lists/oss-security/2023/12/20/2