CVE-2022-33683 describes a vulnerability in Apache Pulsar Brokers and Proxies (versions 2.7.0-2.7.4, 2.8.0-2.8.3, 2.9.0-2.9.2, 2.10.0, and 2.6.4 and earlier) where the internal Pulsar Admin Client fails to verify peer TLS certificates, even when configured to do so. This creates a medium-severity risk (CVSS 5.9) for man-in-the-middle attacks on intra-cluster and geo-replication HTTPS connections, potentially leading to the leakage of authentication and configuration data. Exploitation requires an attacker to control a machine between the client and server and actively manipulate traffic, making it a high attack complexity. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.7.5CPE matchmatch criteria | cpe:2.3:a:apache:pulsar:*:*:*:*:*:*:*:* | ||
>= 2.8.0, < 2.8.4CPE matchmatch criteria | cpe:2.3:a:apache:pulsar:*:*:*:*:*:*:*:* | ||
>= 2.9.0, < 2.9.3CPE matchmatch criteria | cpe:2.3:a:apache:pulsar:*:*:*:*:*:*:*:* | ||
2.10.0CPE matchmatch criteria | cpe:2.3:a:apache:pulsar:2.10.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.