VYPR

Maven package

org.apache.pulsar/pulsar-client

pkg:maven/org.apache.pulsar/pulsar-client

Vulnerabilities (1)

  • CVE-2022-33681Sep 23, 2022
    affected < 2.7.5fixed 2.7.5

    Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in the middle attack. Connections from the Pulsar Java Client to the Pulsar Broker/Proxy and connections from the Pulsar Proxy to the Pulsar Broker are vulnerable