CVE-2016-2141
published 2016-06-30CVE-2016-2141: It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw…
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.70%
90.8th percentile
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libjgroups-java | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jgroups | < 4.0 | 4.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Input Validation in JGroups
osv·2022-05-13
CVE-2016-2141 [CRITICAL] Improper Input Validation in JGroups
Improper Input Validation in JGroups
JGroups before 4.0 does not require the proper headers for the ENCRYPT and AUTH protocols from nodes joining the cluster, which allows remote attackers to bypass security restrictions and send and receive messages within the cluster via unspecified vectors. Fixes for this issue have been backported to versions 3.6.10.Final and 3.2.16.Final.
GHSA
Improper Input Validation in JGroups
ghsa·2022-05-13
CVE-2016-2141 [CRITICAL] CWE-20 Improper Input Validation in JGroups
Improper Input Validation in JGroups
JGroups before 4.0 does not require the proper headers for the ENCRYPT and AUTH protocols from nodes joining the cluster, which allows remote attackers to bypass security restrictions and send and receive messages within the cluster via unspecified vectors. Fixes for this issue have been backported to versions 3.6.10.Final and 3.2.16.Final.
OSV
CVE-2016-2141: It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster
osv·2016-06-30·CVSS 9.8
CVE-2016-2141 [CRITICAL] CVE-2016-2141: It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
Red Hat
JGroups: Authorization bypass
vendor_redhat·2016-06-23·CVSS 9.8
CVE-2016-2141 [CRITICAL] JGroups: Authorization bypass
JGroups: Authorization bypass
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
Mitigation: Please refer to https://access.redhat.com/articles/2360
Debian
CVE-2016-2141: libjgroups-java - It was found that JGroups did not require necessary headers for encrypt and auth...
vendor_debian·2016·CVSS 9.8
CVE-2016-2141 [CRITICAL] CVE-2016-2141: libjgroups-java - It was found that JGroups did not require necessary headers for encrypt and auth...
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2016-1435.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1439.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2035.htmlhttp://www.securityfocus.com/bid/91481http://www.securitytracker.com/id/1036165https://access.redhat.com/errata/RHSA-2016:1345https://access.redhat.com/errata/RHSA-2016:1346https://access.redhat.com/errata/RHSA-2016:1347https://access.redhat.com/errata/RHSA-2016:1374https://access.redhat.com/errata/RHSA-2016:1376https://access.redhat.com/errata/RHSA-2016:1389https://access.redhat.com/errata/RHSA-2016:1432https://access.redhat.com/errata/RHSA-2016:1433https://access.redhat.com/errata/RHSA-2016:1434https://issues.jboss.org/browse/JGRP-2021https://lists.apache.org/thread.html/ra18cac97416abc2958db0b107877c31da28d884fa6e70fd89c87384a%40%3Cdev.geode.apache.org%3Ehttps://lists.apache.org/thread.html/rb37cc937d4fc026fb56de4b4ec0d054aa4083c1a4edd0d8360c068a0%40%3Cdev.geode.apache.org%3Ehttps://rhn.redhat.com/errata/RHSA-2016-1328.htmlhttps://rhn.redhat.com/errata/RHSA-2016-1329.htmlhttps://rhn.redhat.com/errata/RHSA-2016-1330.htmlhttps://rhn.redhat.com/errata/RHSA-2016-1331.htmlhttps://rhn.redhat.com/errata/RHSA-2016-1332.htmlhttps://rhn.redhat.com/errata/RHSA-2016-1333.htmlhttps://rhn.redhat.com/errata/RHSA-2016-1334.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1435.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1439.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2035.htmlhttp://www.securityfocus.com/bid/91481http://www.securitytracker.com/id/1036165https://access.redhat.com/errata/RHSA-2016:1345https://access.redhat.com/errata/RHSA-2016:1346https://access.redhat.com/errata/RHSA-2016:1347https://access.redhat.com/errata/RHSA-2016:1374https://access.redhat.com/errata/RHSA-2016:1376https://access.redhat.com/errata/RHSA-2016:1389https://access.redhat.com/errata/RHSA-2016:1432https://access.redhat.com/errata/RHSA-2016:1433https://access.redhat.com/errata/RHSA-2016:1434https://issues.jboss.org/browse/JGRP-2021https://lists.apache.org/thread.html/ra18cac97416abc2958db0b107877c31da28d884fa6e70fd89c87384a%40%3Cdev.geode.apache.org%3Ehttps://lists.apache.org/thread.html/rb37cc937d4fc026fb56de4b4ec0d054aa4083c1a4edd0d8360c068a0%40%3Cdev.geode.apache.org%3Ehttps://rhn.redhat.com/errata/RHSA-2016-1328.htmlhttps://rhn.redhat.com/errata/RHSA-2016-1329.htmlhttps://rhn.redhat.com/errata/RHSA-2016-1330.htmlhttps://rhn.redhat.com/errata/RHSA-2016-1331.htmlhttps://rhn.redhat.com/errata/RHSA-2016-1332.htmlhttps://rhn.redhat.com/errata/RHSA-2016-1333.htmlhttps://rhn.redhat.com/errata/RHSA-2016-1334.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
2016-06-30
Published