VYPR

Pulsar WebSocket Proxy

by Apache

Source repositories

CVEs (2)

  • CVE-2023-37544Dec 20, 2023
    risk 0.00cvss epss 0.00

    Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication. This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 through 2.9.*, from 2.10.0 through…

  • CVE-2022-33682Sep 23, 2022
    risk 0.00cvss epss 0.00

    TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, the Pulsar WebSocket Proxy's Java Client, and the Pulsar Proxy's Admin Client leaving intra-cluster connections and geo-replication connections vulnerable to…