6.5
CVSSv3

CVE-2020-17520

CVSSv4: NA | CVSSv3: 6.5 | CVSSv2: 4 | VMScore: 750 | EPSS: 0.00331 | KEV: Not Included
Published: 18/12/2020 Updated: 21/11/2024

Vulnerability Summary

In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing special URLs, thereby accessing any HTTP API.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

* pulsar manager

apache pulsar manager 0.1.0

Mailing Lists

CVE-2020-17520 Apache Pulsar Manager Information Disclosure Severity: High Vendor: The Apache Software Foundation Versions Affected: Apache Pulsar Manager 010 Description In Pulsar manager 010 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing special URLs, thereby acces ...