oss-sec mailing list archives

CVE-2020-17520 Apache Pulsar Manager Information Disclosure (bypass admin interceptor)


From: Guangning E <guangning () apache org>
Date: Thu, 17 Dec 2020 17:45:12 +0800

CVE-2020-17520 Apache Pulsar Manager Information Disclosure

Severity: High

Vendor: The Apache Software Foundation

Versions Affected:
Apache Pulsar Manager 0.1.0

Description
In Pulsar manager 0.1.0 version, malicious users will be able to bypass
pulsar-manager's admin, permission verification mechanism by constructing
special URLs, thereby accessing any HTTP API

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Pulsar Manager 0.2.0 or later

Credit:
This issue was identified by the threedr3am.

Current thread: