CVE-2024-27894
Last modified
CVE-2024-27894 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported URL schemes include "file", "http", and "https". EPSS estimates a 1.90% chance of exploitation in the next 30 days.
Description
The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported URL schemes include "file", "http", and "https". When a function is created using this method, the Functions Worker will retrieve the implementation from the URL provided by the user. However, this feature introduces a vulnerability that can be exploited by an attacker to gain unauthorized access to any file that the Pulsar Functions Worker process has permissions to read. This includes reading the process environment which potentially includes sensitive information, such as secrets. Furthermore, an attacker could leverage this vulnerability to use the Pulsar Functions Worker as a proxy to access the content of remote HTTP and HTTPS endpoint URLs. This could also be used to carry out denial of service attacks. This vulnerability also applies to the Pulsar Broker when it is configured with "functionsWorkerEnabled=true". This issue affects Apache Pulsar versions from 2.4.0 to 2.10.5, from 2.11.0 to 2.11.3, from 3.0.0 to 3.0.2, from 3.1.0 to 3.1.2, and 3.2.0. 2.10 Pulsar Function Worker users should upgrade to at least 2.10.6. 2.11 Pulsar Function Worker users should upgrade to at least 2.11.4. 3.0 Pulsar Function Worker users should upgrade to at least 3.0.3. 3.1 Pulsar Function Worker users should upgrade to at least 3.1.3. 3.2 Pulsar Function Worker users should upgrade to at least 3.2.1. Users operating versions prior to those listed above should upgrade to the aforementioned patched versions or newer versions. The updated versions of Pulsar Functions Worker will, by default, impose restrictions on the creation of functions using URLs. For users who rely on this functionality, the Function Worker configuration provides two configuration keys: "additionalEnabledConnectorUrlPatterns" and "additionalEnabledFunctionsUrlPatterns". These keys allow users to specify a set of URL patterns that are permitted, enabling the creation of functions using URLs that match the defined patterns. This approach ensures that the feature remains available to those who require it, while limiting the potential for unauthorized access and exploitation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Pulsar | >= 2.4.0, < 2.10.6 |
| Apache | Pulsar | >= 2.11.0, < 2.11.4 |
| Apache | Pulsar | >= 3.0.0, < 3.0.3 |
| Apache | Pulsar | >= 3.1.0, < 3.1.3 |
| Apache | Pulsar | 3.2.0 |
References
- http://www.openwall.com/lists/oss-security/2024/03/12/11Mailing List, Third Party Advisory
- https://pulsar.apache.org/security/CVE-2024-27894/Vendor Advisory
- http://www.openwall.com/lists/oss-security/2024/03/12/11Mailing List, Third Party Advisory
- https://pulsar.apache.org/security/CVE-2024-27894/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-27894?
How severe is CVE-2024-27894?
How do I fix CVE-2024-27894?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-27888A permissions issue was addressed by removing vulnerable cod…5.5
- CVE-2024-27889Multiple SQL Injection vulnerabilities exist in the reportin…8.8
- CVE-2024-2789The Happy Addons for Elementor plugin for WordPress is vulne…5.4
- CVE-2024-27890Affected platforms running Arista EOS with OpenConfig config…9.6
- CVE-2024-27891On affected platforms running Arista EOS with MACsec and egr…6.9
- CVE-2024-27892Affected platforms running Arista EOS with OpenConfig config…9.6
- CVE-2024-27895Vulnerability of permission control in the window module. Su…7.5
- CVE-2024-27896Input verification vulnerability in the log module. Impact: …7.5
- CVE-2024-27897Input verification vulnerability in the call module. Impact:…7.5
- CVE-2024-27898SAP NetWeaver application, due to insufficient input validat…5.3
- CVE-2024-27899Self-Registration and Modify your own profile in User Admin …8.8
- CVE-2024-2790The HT Mega – Absolute Addons For Elementor plugin for WordP…5.4
Are you affected by CVE-2024-27894?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
