JGroups before 4.0 does not require the proper headers for the ENCRYPT and AUTH protocols from nodes joining the cluster, which allows remote attackers to bypass security restrictions and send and receive messages within the cluster via unspecified vectors.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Information
Published : 2016-06-30 09:59
Updated : 2022-02-25 08:37
NVD link : CVE-2016-2141
Mitre link : CVE-2016-2141
JSON object : View
CWE
Products Affected
redhat
- jgroups
- enterprise_linux
- jboss_enterprise_application_platform