
====================================================================

                             CERT-Renater

                 Note d'Information No. 2020/VULN695
_____________________________________________________________________

DATE                : 17/12/2020

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache Pulsar Manager versions
                                    prior to 0.2.0.

=====================================================================
http://mail-archives.apache.org/mod_mbox/www-announce/202012.mbox/%3cCACYv8z0teodkY_4Zy-Q56VuVZm40cfM2myoQLVeq56y8ouTY-g@mail.gmail.com%3e
_____________________________________________________________________

CVE-2020-17520 Apache Pulsar Manager Information Disclosure

Severity: High

Vendor: The Apache Software Foundation

Versions Affected:
Apache Pulsar Manager 0.1.0

Description
In Pulsar manager 0.1.0 version, malicious users will be able to bypass
pulsar-manager's admin, permission verification mechanism by
constructing special URLs, thereby accessing any HTTP API

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Pulsar Manager 0.2.0 or later

Credit:
This issue was identified by the threedr3am.

=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================

	


