VYPR

Maven package

org.apache.pulsar/pulsar-websocket

pkg:maven/org.apache.pulsar/pulsar-websocket

Vulnerabilities (1)

  • CVE-2023-37544Dec 20, 2023
    affected < 2.10.5fixed 2.10.5

    Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication. This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 through 2.9.*, from 2.10.0 through 2.10.4