CVE-2013-4112Sensitive Information Exposure in Jgroup

Severity
5.4MEDIUMNVD
EPSS
0.6%
top 29.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 28
Latest updateMay 17

Description

The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.

CVSS vector

AV:A/AC:M/C:P/I:P/A:PExploitability: 5.5 | Impact: 6.4

Affected Packages2 packages

🔴Vulnerability Details

4
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in JGroup2022-05-17
OSV
Exposure of Sensitive Information to an Unauthorized Actor in JGroup2022-05-17
OSV
CVE-2013-4112: The DiagnosticsHandler in JGroup 32013-09-28
CVEList
CVE-2013-4112: The DiagnosticsHandler in JGroup 32013-09-28

📋Vendor Advisories

2
Red Hat
JGroups: Authentication via cached credentials2013-07-11
Debian
CVE-2013-4112: libjgroups-java - The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x bef...2013

💬Community

2
Bugzilla
jgroups: CVE-2013-4112 JGroups: Authentication via cached credentials [brms-5]2013-07-15
Bugzilla
CVE-2013-4112 JGroups: Authentication via cached credentials2013-07-11
CVE-2013-4112 — Sensitive Information Exposure | cvebase