apache pulsar 证书验证不恰当

admin 2023-11-30 05:53:20 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
中危 apache pulsar 证书验证不恰当

CVE编号

CVE-2022-33681

利用情况

暂无

补丁情况

官方补丁

披露时间

2022-09-23
漏洞描述
Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in the middle attack. Connections from the Pulsar Java Client to the Pulsar Broker/Proxy and connections from the Pulsar Proxy to the Pulsar Broker are vulnerable. Authentication data is sent before verifying the server’s TLS certificate matches the hostname, which means authentication data could be exposed to an attacker. An attacker can only take advantage of this vulnerability by taking control of a machine 'between' the client and the server. The attacker must then actively manipulate traffic to perform the attack by providing the client with a cryptographically valid certificate for an unrelated host. Because the client sends authentication data before performing hostname verification, an attacker could gain access to the client’s authentication data. The client eventually closes the connection when it verifies the hostname and identifies the targeted hostname does not match a hostname on the certificate. Because the client eventually closes the connection, the value of the intercepted authentication data depends on the authentication method used by the client. Token based authentication and username/password authentication methods are vulnerable because the authentication data can be used to impersonate the client in a separate session. This issue affects Apache Pulsar Java Client versions 2.7.0 to 2.7.4; 2.8.0 to 2.8.3; 2.9.0 to 2.9.2; 2.10.0; 2.6.4 and earlier.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://lists.apache.org/thread/fpo6x10trvn20hlk0dmnr5vlz5v4kl3d
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 apache pulsar * Up to (excluding) 2.7.5
运行在以下环境
应用 apache pulsar * From (including) 2.8.0 Up to (excluding) 2.8.4
运行在以下环境
应用 apache pulsar * From (including) 2.9.0 Up to (excluding) 2.9.3
运行在以下环境
应用 apache pulsar 2.10.0 -
阿里云评分 5.4
  • 攻击路径 本地
  • 攻击复杂度 困难
  • 权限要求 管控权限
  • 影响范围 有限影响
  • EXP成熟度 未验证
  • 补丁情况 官方补丁
  • 数据保密性 无影响
  • 数据完整性 无影响
  • 服务器危害 无影响
  • 全网数量 N/A
CWE-ID 漏洞类型
CWE-295 证书验证不恰当
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0