GHSA-rc7h-x6cq-988q

    Dashboard / Vulnerabilities / GHSA-rc7h-x6cq-988q

    GHSA-rc7h-x6cq-988q

    Published: 13 May 2022Last Modified: 9 Mar 2024
    Aliases:

    Summary: Improper Input Validation in JGroups

    Details: JGroups before 4.0 does not require the proper headers for the ENCRYPT and AUTH protocols from nodes joining the cluster, which allows remote attackers to bypass security restrictions and send and receive messages within the cluster via unspecified vectors. Fixes for this issue have been backported to versions 3.6.10.Final and 3.2.16.Final.

    References: https://nvd.nist.gov/vuln/detail/CVE-2016-2141, https://github.com/belaban/JGroups/commit/eeaf5241cce464ef21a2dfc4938729ade9ebef36, https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html, https://web.archive.org/web/20201207092245/http://www.securitytracker.com/id/1036165, https://web.archive.org/web/20161013163606/http://www.securityfocus.com/bid/91481, https://rhn.redhat.com/errata/RHSA-2016-1334.html, https://rhn.redhat.com/errata/RHSA-2016-1333.html, https://rhn.redhat.com/errata/RHSA-2016-1332.html, https://rhn.redhat.com/errata/RHSA-2016-1331.html, https://rhn.redhat.com/errata/RHSA-2016-1330.html, https://rhn.redhat.com/errata/RHSA-2016-1329.html, https://rhn.redhat.com/errata/RHSA-2016-1328.html, https://lists.apache.org/thread.html/rb37cc937d4fc026fb56de4b4ec0d054aa4083c1a4edd0d8360c068a0@%3Cdev.geode.apache.org%3E, https://lists.apache.org/thread.html/ra18cac97416abc2958db0b107877c31da28d884fa6e70fd89c87384a@%3Cdev.geode.apache.org%3E, https://issues.redhat.com/browse/JGRP-2074, https://issues.redhat.com/browse/JGRP-2055, https://issues.jboss.org/browse/JGRP-2021, https://github.com/belaban/JGroups, https://access.redhat.com/errata/RHSA-2016:1434, https://access.redhat.com/errata/RHSA-2016:1433, https://access.redhat.com/errata/RHSA-2016:1432, https://access.redhat.com/errata/RHSA-2016:1389, https://access.redhat.com/errata/RHSA-2016:1376, https://access.redhat.com/errata/RHSA-2016:1374, https://access.redhat.com/errata/RHSA-2016:1347, https://access.redhat.com/errata/RHSA-2016:1346, https://access.redhat.com/errata/RHSA-2016:1345, http://rhn.redhat.com/errata/RHSA-2016-1435.html, http://rhn.redhat.com/errata/RHSA-2016-1439.html, http://rhn.redhat.com/errata/RHSA-2016-2035.html

    Affected packages

    Package

    Name: org.jgroups:jgroups

    Purl: pkg:maven/org.jgroups/jgroups

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 3.3.0.Alpha1
    Fixed -3.6.10.Final

    Affected versions

    3.3.0.Alpha1
    3.3.0.Alpha2
    3.3.0.Beta1
    3.3.0.Beta2
    3.3.0.Beta3
    3.3.0.CR1
    3.3.0.CR2
    3.3.0.Final
    3.3.1.Final
    3.3.2.Final
    3.3.3.Final
    3.3.4.Final
    3.3.5.Final
    3.3.6.Final

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-rc7h-x6cq-988q | CVE-DB