GHSA-83q5-whqp-r8jr
HIGHCVE-2023-37544Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication.
- Affected
- < 2.10.5, >= 2.11.0, < 2.11.2, >= 3.0.0, < 3.0.1
- Fixed in
- 2.10.5
- Weakness
- CWE-287
- Published
- 2023-12-20
- Source
- github