Vulnerabilities > Apache > Pulsar > 3.0.2

DATE CVE VULNERABILITY TITLE RISK
2024-04-02 CVE-2024-29834 Unspecified vulnerability in Apache Pulsar
This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering compaction.
network
low complexity
apache
6.4
2024-03-12 CVE-2024-27135 Unspecified vulnerability in Apache Pulsar
Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions.
network
low complexity
apache
critical
9.9
2024-03-12 CVE-2024-27317 Unspecified vulnerability in Apache Pulsar
In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files.
network
low complexity
apache
critical
9.9
2024-03-12 CVE-2024-27894 Unspecified vulnerability in Apache Pulsar
The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL.
network
low complexity
apache
8.8
2024-03-12 CVE-2024-28098 Unspecified vulnerability in Apache Pulsar
The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings.
network
low complexity
apache
5.4