CVE-2016-2141
CRITICALJGroups 3.3.0.Alpha1-3.6.10.Final - Unauthenticated Cluster Message Spoofing and Information Disclosure
Title source: llmDescription
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
References (25)
Core 25
Core References
Vendor Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2016-2035.html
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1345
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1376
Vendor Advisory vendor-advisory
https://rhn.redhat.com/errata/RHSA-2016-1330.html
Vendor Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2016-1439.html
Broken Link, Vendor Advisory vendor-advisory
https://rhn.redhat.com/errata/RHSA-2016-1331.html
VDB Entry vdb-entry
http://www.securityfocus.com/bid/91481
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1434
Vendor Advisory vendor-advisory
https://rhn.redhat.com/errata/RHSA-2016-1328.html
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1433
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1374
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1432
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1346
Vendor Advisory vendor-advisory
https://rhn.redhat.com/errata/RHSA-2016-1334.html
Broken Link, Vendor Advisory vendor-advisory
https://rhn.redhat.com/errata/RHSA-2016-1333.html
Broken Link, Vendor Advisory vendor-advisory
https://rhn.redhat.com/errata/RHSA-2016-1329.html
Vendor Advisory vendor-advisory
https://rhn.redhat.com/errata/RHSA-2016-1332.html
Vendor Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2016-1435.html
Broken Link, Third Party Advisory, VDB Entry vdb-entry
http://www.securitytracker.com/id/1036165
Mailing List mailing-list
https://lists.apache.org/thread.html/ra18cac97416abc2958db0b107877c31da28d884fa6e70fd89c87384a%40%3Cdev.geode.apache.org%3E
Issue Tracking, Vendor Advisory
https://issues.jboss.org/browse/JGRP-2021
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1347
Patch, Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1389
Scores
CVSS v3
9.8
EPSS
0.0470
EPSS Percentile
90.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (5)
org.jgroups/jgroups
3.3.0.Alpha1 - 3.6.10.FinalMaven
redhat/jboss_enterprise_application_platform
5.2
redhat/jboss_enterprise_application_platform
6.4
redhat/jboss_enterprise_application_platform
7.0
redhat/jgroups
< 4.0
Published
Jun 30, 2016
Tracked Since
Feb 18, 2026