GHSA-c5fp-x2h5-vjv7
MODERATECVE-2022-33681Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in the middle attack. Connections from the Pulsar Java Client to the Pulsar Broker/Proxy and connections from the Pulsar Proxy to the Pulsar Broker are vulnerable. Authentication data is sent before verifying the server’s TLS certificate matches the hostname, which means authentica
- Affected
- >= 2.9.0, < 2.9.3, >= 2.8.0, < 2.8.4, = 2.10.0, < 2.7.5
- Fixed in
- 2.9.3
- Weakness
- CWE-295
- Published
- 2022-09-25
- Source
- github