CVE-2013-4112
published 2013-09-28CVE-2013-4112: The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic…
PriorityP430medium5.4CVSS 2.0
AVAACMAuNCPIPAP
EPSS
1.61%
73.2th percentile
The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libjgroups-java | < libjgroups-java 2.12.2.Final-4 (bookworm) | libjgroups-java 2.12.2.Final-4 (bookworm) |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
| jgroups | jgroup | — | — |
CVSS provenance
nvdv2.05.4MEDIUMAV:A/AC:M/Au:N/C:P/I:P/A:P
osv5.4MEDIUM
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JGroups: Authentication via cached credentials
vendor_redhat·2013-07-11·CVSS 5.4
CVE-2013-4112 [MEDIUM] JGroups: Authentication via cached credentials
JGroups: Authentication via cached credentials
The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.
Package: jgroups (Red Hat JBoss BRMS 5) - Not affected
Package: jgroups (Red Hat JBoss Enterprise Application Platform 5) - Not affected
Package: jgroups (Red Hat JBoss Operations Network 3) - Not affected
Package: jgroups (Red Hat JBoss Portal 4) - Not affected
Package: jgroups (Red Hat JBoss Portal 5) - Not affected
Package: jgroups (Red Hat JBoss SOA Platform 4) - Not affected
Package: jgroups (Red Hat JBoss SOA Platform 5) - Not affected
Debian
CVE-2013-4112: libjgroups-java - The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x bef...
vendor_debian·2013·CVSS 5.4
CVE-2013-4112 [MEDIUM] CVE-2013-4112: libjgroups-java - The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x bef...
The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.
Scope: local
bookworm: resolved (fixed in 2.12.2.Final-4)
bullseye: resolved (fixed in 2.12.2.Final-4)
forky: resolved (fixed in 2.12.2.Final-4)
sid: resolved (fixed in 2.12.2.Final-4)
trixie: resolved (fixed in 2.12.2.Final-4)
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in JGroup
ghsa·2022-05-17
CVE-2013-4112 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in JGroup
Exposure of Sensitive Information to an Unauthorized Actor in JGroup
The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in JGroup
osv·2022-05-17
CVE-2013-4112 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in JGroup
Exposure of Sensitive Information to an Unauthorized Actor in JGroup
The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.
OSV
CVE-2013-4112: The DiagnosticsHandler in JGroup 3
osv·2013-09-28·CVSS 5.4
CVE-2013-4112 [MEDIUM] CVE-2013-4112: The DiagnosticsHandler in JGroup 3
The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.
No detection rules found.
No public exploits indexed.
Bugzilla
jgroups: CVE-2013-4112 JGroups: Authentication via cached credentials [brms-5]
bugzilla·2013-07-15·CVSS 5.4
CVE-2013-4112 [MEDIUM] jgroups: CVE-2013-4112 JGroups: Authentication via cached credentials [brms-5]
jgroups: CVE-2013-4112 JGroups: Authentication via cached credentials [brms-5]
brms-5 tracking bug for jgroups: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the blocked bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
EAP-5 fix is handled in [jira JBPAPP-10817]
---
This is to be considered as a security hardening fix.
Bugzilla
CVE-2013-4112 JGroups: Authentication via cached credentials
bugzilla·2013-07-11·CVSS 5.4
CVE-2013-4112 [MEDIUM] CVE-2013-4112 JGroups: Authentication via cached credentials
CVE-2013-4112 JGroups: Authentication via cached credentials
A flaw was found in JGroup's DiagnosticsHandler that allowed an attacker on an adjacent network to reuse the credentials from a previous successful authentication. This could be exploited to read diagnostic information (information disclosure) and attain limited remote code execution.
This issue affects JGroups versions 3.0.x (3.0.11.Final and later), 3.1.x (3.1.0.Final and later), 3.2.x (prior to 3.2.10.Final) and 3.3.x (prior to 3.3.3.Final).
Discussion:
This issue was fixed in upstream versions 3.3.3.Final and 3.2.10.Final.
---
Will 3.2.10 be certified for EAP ? (To be consumed in JPP 6.1)
---
This issue has been addressed in following products:
Red Hat JBoss Enterprise Application Platform 6.1.1
Via RHSA-2013:1209 h
http://rhn.redhat.com/errata/RHSA-2013-1207.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1208.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1209.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1437.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1771.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0029.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=983489http://rhn.redhat.com/errata/RHSA-2013-1207.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1208.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1209.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1437.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1771.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0029.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=983489
2013-09-28
Published