CVE-2016-2141

EUVD-2022-5146
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
Affected Products (NVD)
VendorProductVersion
redhatjgroups
𝑥
< 4.0
redhatjboss_enterprise_application_platform
5.2
redhatjboss_enterprise_application_platform
6.4
redhatjboss_enterprise_application_platform
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libjgroups-java
bookworm
ignored
bullseye
ignored
buster
ignored
jessie
no-dsa
sid
vulnerable
stretch
ignored
trixie
vulnerable
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libjgroups-java
artful
ignored
bionic
needed
cosmic
ignored
disco
ignored
eoan
ignored
focal
needed
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needed
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needed
precise
ignored
trusty
dne
wily
ignored
xenial
needed
yakkety
ignored
zesty
ignored
References