peter bassill · operator
$ cve CVE-2021-22160 JSON

CVE-2021-22160

9.8
CRITICAL · CVSS 3.1 · EPSS 52.9% (pctl 99)

Patch early

EPSS 52.9% — above the 10% action threshold.

Description

If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none". This allows an attacker to connect to Pulsar instances as any user (incl. admins).

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS52.93% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-347
On CISA KEVno
Public exploitnone known
Published2021-05-26
Last modified2026-06-17

Affected (1)

VendorProduct
apachepulsar

References

→ the Explorer  ·  watch your stack  ·  NVD