AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-22160

CRITICAL · CVSS 9.8 EPSS 52.93%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-05-26 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Apache. Its EPSS score suggests a 52.9% probability of exploitation in the next 30 days.

CVE
CVE-2021-22160
Severity
CRITICAL
CVSS
9.8
EPSS
52.93%
Apache

Original NVD Description

If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none". This allows an attacker to connect to Pulsar instances as any user (incl. admins).

Related CVEs

Other vulnerabilities affecting the same vendor(s)