GHSA-cc62-496p-hrr7
Dashboard / Vulnerabilities / GHSA-cc62-496p-hrr7
Summary: Exposure of Sensitive Information to an Unauthorized Actor in JGroup
Details: The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.
References: https://nvd.nist.gov/vuln/detail/CVE-2013-4112, https://bugzilla.redhat.com/show_bug.cgi?id=983489, http://rhn.redhat.com/errata/RHSA-2013-1207.html, http://rhn.redhat.com/errata/RHSA-2013-1208.html, http://rhn.redhat.com/errata/RHSA-2013-1209.html, http://rhn.redhat.com/errata/RHSA-2013-1437.html, http://rhn.redhat.com/errata/RHSA-2013-1771.html, http://rhn.redhat.com/errata/RHSA-2014-0029.html
Affected packages
Package
Name: org.jgroups:jgroups
Purl: pkg:maven/org.jgroups/jgroups
Affected ranges
Type: ECOSYSTEM
Events:
