CVE-2021-22160 is a critical vulnerability affecting Apache Pulsar when configured for JWT-based client authentication. It allows an attacker to bypass authentication by presenting a token with the algorithm set to "none," effectively impersonating any user, including administrators. With a CVSS score of 9.8, this network-exploitable flaw requires no user interaction and can lead to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its high severity warrants immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.7.1CPE matchmatch criteria | cpe:2.3:a:apache:pulsar:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.