Improper Input Validation in JGroups
Critical severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jun 1, 2023
Package
Affected versions
>= 3.3.0.Alpha1, < 3.6.10.Final
< 3.2.16.Final
Patched versions
3.6.10.Final
3.2.16.Final
Description
Published by the National Vulnerability Database
Jun 30, 2016
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 6, 2022
Last updated
Jun 1, 2023
JGroups before 4.0 does not require the proper headers for the ENCRYPT and AUTH protocols from nodes joining the cluster, which allows remote attackers to bypass security restrictions and send and receive messages within the cluster via unspecified vectors. Fixes for this issue have been backported to versions 3.6.10.Final and 3.2.16.Final.
References