CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It affects Apache. Its EPSS score suggests a 52.9% probability of exploitation in the next 30 days.
CVE
CVE-2021-22160
Severity
CRITICAL
CVSS
9.8
EPSS
52.93%
Apache
Original NVD Description
If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none". This allows an attacker to connect to Pulsar instances as any user (incl. admins).
Related CVEs
Other vulnerabilities affecting the same vendor(s)