You are viewing a plain text version of this content. The canonical link for it is here.
Posted to announce@apache.org by Guangning E <gu...@apache.org> on 2020/12/17 09:39:55 UTC
[SECURITY] [CVE-2020-17520] Pulsar Manager security bug(bypass admin interceptor)
CVE-2020-17520 Apache Pulsar Manager Information Disclosure
Severity: High
Vendor: The Apache Software Foundation
Versions Affected:
Apache Pulsar Manager 0.1.0
Description
In Pulsar manager 0.1.0 version, malicious users will be able to bypass
pulsar-manager's admin, permission verification mechanism by constructing
special URLs, thereby accessing any HTTP API
Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Pulsar Manager 0.2.0 or later
Credit:
This issue was identified by the threedr3am.