HTTP: Apache Pulsar JSON Web Token Authentication Bypass

This signature detects attempts to exploit a known vulnerability against Apache Pulsar JSON Web Token. A successful attack can lead to security bypass.

Extended Description

If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none". This allows an attacker to connect to Pulsar instances as any user (incl. admins).

Affected Products

Apache pulsar

Short Name
HTTP:APACHE:PULSAR-JWT-AUTH
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Apache Authentication Bypass CVE-2021-22160 JSON Pulsar Token Web
Release Date
09/16/2021
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3419
False Positive
Unknown
Vendors

Apache

CVSS Score

7.5

Found a potential security threat?