CVE-2016-2141
An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.70% probability · 91th percentile
- CISA KEV
- Not listed
- Affected
- redhat/jgroups · redhat/jboss enterprise application platform
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2016-1435.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1439.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2035.htmlVendor Advisory
- http://www.securityfocus.com/bid/91481VDB Entry
- http://www.securitytracker.com/id/1036165Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:1345Vendor Advisory
- https://access.redhat.com/errata/RHSA-2016:1346Vendor Advisory
- https://access.redhat.com/errata/RHSA-2016:1347Vendor Advisory
- https://access.redhat.com/errata/RHSA-2016:1374Vendor Advisory
- https://access.redhat.com/errata/RHSA-2016:1376Vendor Advisory
- https://access.redhat.com/errata/RHSA-2016:1389Vendor Advisory
- https://access.redhat.com/errata/RHSA-2016:1432Vendor Advisory
- https://access.redhat.com/errata/RHSA-2016:1433Vendor Advisory
- https://access.redhat.com/errata/RHSA-2016:1434Vendor Advisory
- https://issues.jboss.org/browse/JGRP-2021Issue Tracking, Vendor Advisory
- https://lists.apache.org/thread.html/ra18cac97416abc2958db0b107877c31da28d884fa6e70fd89c87384a%40%3Cdev.geode.apache.org%3E
- https://lists.apache.org/thread.html/rb37cc937d4fc026fb56de4b4ec0d054aa4083c1a4edd0d8360c068a0%40%3Cdev.geode.apache.org%3E
- https://rhn.redhat.com/errata/RHSA-2016-1328.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2016-1329.htmlBroken Link, Vendor Advisory
- https://rhn.redhat.com/errata/RHSA-2016-1330.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2016-1331.htmlBroken Link, Vendor Advisory
- https://rhn.redhat.com/errata/RHSA-2016-1332.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2016-1333.htmlBroken Link, Vendor Advisory
- https://rhn.redhat.com/errata/RHSA-2016-1334.htmlVendor Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1435.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1439.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2035.htmlVendor Advisory
- http://www.securityfocus.com/bid/91481VDB Entry
- http://www.securitytracker.com/id/1036165Broken Link, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.