Insufficient Session Expiration Affecting org.apache.pulsar:pulsar-broker package, versions [,2.9.5)[2.10.0,2.10.4)[2.11.0,2.11.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.02% (60th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHEPULSAR-5772251
  • published12 Jul 2023
  • disclosed12 Jul 2023
  • creditUnknown

Introduced: 12 Jul 2023

CVE-2023-31007  (opens in a new tab)
CWE-613  (opens in a new tab)

How to fix?

Upgrade org.apache.pulsar:pulsar-broker to version 2.9.5, 2.10.4, 2.11.1 or higher.

Overview

Affected versions of this package are vulnerable to Insufficient Session Expiration which allows a client to stay connected to a broker after authentication data expires if the client connected through the Pulsar Proxy when the broker is configured with authenticateOriginalAuthData=false or if a client connects directly to a broker with a specially crafted connect command when the broker is configured with authenticateOriginalAuthData=false.

CVSS Base Scores

version 3.1