CVE-2022-33683 - CVE House
Back to Database
Status published Unknown CVE-2022-33683

Disabled Certificate Validation makes Broker, Proxy Admin Clients vulnerable to MITM attack

Vulnerability Description

Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, even when tlsAllowInsecureConnection is disabled via configuration. The Pulsar Admin Client's intra-cluster and geo-replication HTTPS connections are vulnerable to man in the middle attacks, which could leak authentication data, configuration data, and any other data sent by these clients. An attacker can only take advantage of this vulnerability by taking control of a machine 'between' the client and the server. The attacker must then actively manipulate traffic to perform the attack. This issue affects Apache Pulsar Broker and Proxy versions 2.7.0 to 2.7.4; 2.8.0 to 2.8.3; 2.9.0 to 2.9.2; 2.10.0; 2.6.4 and earlier.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-33683

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This issue was discovered by Michael Marshall of DataStax.

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache Pulsar
Vulnerable Versions:
2.10.0, 2.7, 2.8, 2.9, 2.6 and earlier

Timeline

Official Publish: September 23rd, 2022
Last Modified: May 22nd, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)