{"id":"GHSA-3cv4-xxv7-934q","summary":"Improper Verification of Cryptographic Signature in Apache Pulsar in TensorFlow","details":"If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to \"none\". This allows an attacker to connect to Pulsar instances as any user (incl. admins).","aliases":["CVE-2021-22160"],"modified":"2023-11-08T04:04:54.864716Z","published":"2021-06-01T21:53:49Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-06-01T20:20:10Z","nvd_published_at":"2021-05-26T13:15:00Z","cwe_ids":["CWE-347"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-22160"},{"type":"WEB","url":"https://github.com/apache/pulsar/releases/tag/v2.7.2"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r08c7df60cae031361df7fbac39d08b6d5b5079e74db5195d409db9a2@%3Cdev.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r347650d15a3e9c5f58b83e918b6ad6dedc2a63d3eb63da8e6a7be87e%40%3Cusers.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r8e545559781231a83bf0644548c660255859e52feb86bbfcd42590da@%3Cdev.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r9a12b4da2f26ce9b8f7e7117a879efaa973dab7e54717bbc7923fab1%40%3Cdev.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/ra49cb62105154e4795b259c79a6b27d63bfa2ab5787ff8529b089550@%3Cdev.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/ra49cb62105154e4795b259c79a6b27d63bfa2ab5787ff8529b089550@%3Cusers.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rbe845aa1573a61769b9c5916c62971f4b10de87c2ea5f38a97f0cf84@%3Cdev.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rca54f4b26ba5e6f2e39732b47ec51640e89f57e3b6a38ac3bab314df@%3Cdev.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/re2ae364e0c02093dc721699698c6f23cfbba0220c78b5e28cafeae81@%3Ccommits.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rf2e90942996dceebac8296abf39257cfeb5ae918f82f7af3d37a48c5@%3Cdev.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rf54fefc25c49d4715d484133d438f13bf2e515a5fed5d3a745d4f6e7@%3Ccommits.pulsar.apache.org%3E"}],"affected":[{"package":{"name":"org.apache.pulsar:pulsar","ecosystem":"Maven","purl":"pkg:maven/org.apache.pulsar/pulsar"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.2"}]}],"versions":["1.19.0-incubating","1.20.0-incubating","1.21.0-incubating","1.22.0-incubating","1.22.1-incubating","2.0.0-rc1-incubating","2.0.1-incubating","2.1.0-incubating","2.1.1-incubating","2.2.0","2.2.1","2.3.0","2.3.1","2.3.2","2.4.0","2.4.1","2.4.2","2.5.0","2.5.1","2.5.2","2.6.0","2.6.1","2.6.2","2.6.3","2.6.4","2.7.0","2.7.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-3cv4-xxv7-934q/GHSA-3cv4-xxv7-934q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}