CVE-2023-30429

Source
https://cve.org/CVERecord?id=CVE-2023-30429
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-30429.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-30429
Aliases
Published
2023-07-12T09:08:23.703Z
Modified
2026-08-12T03:51:31.600035594Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Apache Pulsar: Incorrect Authorization for Function Worker when using mTLS Authentication through Pulsar Proxy
Details

Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar.

This issue affects Apache Pulsar: before 2.10.4, and 2.11.0.

When a client connects to the Pulsar Function Worker via the Pulsar Proxy where the Pulsar Proxy uses mTLS authentication to authenticate with the Pulsar Function Worker, the Pulsar Function Worker incorrectly performs authorization by using the Proxy's role for authorization instead of the client's role, which can lead to privilege escalation, especially if the proxy is configured with a superuser role.

The recommended mitigation for impacted users is to upgrade the Pulsar Function Worker to a patched version.

2.10 Pulsar Function Worker users should upgrade to at least 2.10.4. 2.11 Pulsar Function Worker users should upgrade to at least 2.11.1. 3.0 Pulsar Function Worker users are unaffected. Any users running the Pulsar Function Worker for 2.9.* and earlier should upgrade to one of the above patched versions.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/30xxx/CVE-2023-30429.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "2.10.4"
                },
                {
                    "introduced": "2.11.0"
                },
                {
                    "last_affected": "2.11.0"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "fixed": "2.10.4"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-863"
    ],
    "cna_assigner": "apache"
}
References

Affected packages

Git / github.com/apache/pulsar

Affected ranges

Type
GIT
Repo
https://github.com/apache/pulsar
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Last affected
Database specific
Show details
{
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ],
    "cpe": [
        "cpe:2.3:a:apache:pulsar:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:pulsar:2.11.0:-:*:*:*:*:*:*",
        "cpe:2.3:a:apache:pulsar:2.11.0:candidate_5:*:*:*:*:*:*",
        "cpe:2.3:a:apache:pulsar:2.11.0:candidate_1:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.10.4"
        },
        {
            "introduced": "2.11.0-NA"
        },
        {
            "last_affected": "2.11.0-NA"
        },
        {
            "introduced": "2.11.0-candidate_5"
        },
        {
            "last_affected": "2.11.0-candidate_5"
        },
        {
            "introduced": "2.11.0-candidate_1"
        },
        {
            "last_affected": "2.11.0-candidate_1"
        }
    ]
}

Affected versions

2.*
2.11.0-NA
2.11.0-candidate_1
v1.*
v1.14
v1.15
v1.16
v1.17
v1.18
v2.*
v2.10.0
v2.10.0-candidate-1
v2.10.0-candidate-2
v2.10.0-candidate-3
v2.10.0-candidate-4
v2.10.0-candidate-5
v2.10.1
v2.10.1-candidate-1
v2.10.2
v2.10.2-candidate-1
v2.10.2-candidate-2
v2.10.2-candidate-3
v2.10.4-candidate-1
v2.10.4-candidate-2
v2.11.0-candidate-1
vx.*
vx.y.z.m

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-30429.json"