CVE-2024-27317 is a critical directory traversal vulnerability in Apache Pulsar Functions Worker and Broker (when functionsWorkerEnabled=true), affecting multiple versions from 2.4.0 up to 3.2.0. Authenticated attackers can upload malicious jar or nar files containing specially crafted filenames with ".." sequences, allowing them to create or modify arbitrary files outside the intended extraction directory. This vulnerability carries a CVSS score of 9.9 (Critical) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.0, < 2.10.6CPE matchmatch criteria | cpe:2.3:a:apache:pulsar:*:*:*:*:*:*:*:* | ||
>= 2.11.0, < 2.11.4CPE matchmatch criteria | cpe:2.3:a:apache:pulsar:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.0.3CPE matchmatch criteria | cpe:2.3:a:apache:pulsar:*:*:*:*:*:*:*:* | ||
>= 3.1.0, < 3.1.3CPE matchmatch criteria | cpe:2.3:a:apache:pulsar:*:*:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:apache:pulsar:3.2.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Pulsar: Pulsar Functions Worker's Archive Extraction Vulnerability Allows Unauthorized File Modification
Mar 12, 2024apache-pulsar: Pulsar Functions Worker's Archive Extraction Vulnerability Allows Unauthorized File Modification
Mar 12, 2024