cbcvebase.
CVE-2022-32531
published 2022-12-15

CVE-2022-32531: The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails…

PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
1.02%
59.5th percentile
The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails. This leaves the bookkeeper client vulnerable to a man in the middle attack. The problem affects BookKeeper client prior to versions 4.14.6 and 4.15.1.

Affected

4 ranges
VendorProductVersion rangeFixed in
apachebookkeeper< 4.14.64.14.6
apachebookkeeper
apache_software_foundationapache_bookkeeper<= 4.14.5
apache_software_foundationapache_bookkeeper

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
osv5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.