CVE-2016-2141

CRITICAL

JGroups 3.3.0.Alpha1-3.6.10.Final - Unauthenticated Cluster Message Spoofing and Information Disclosure

Title source: llm
STIX 2.1

Description

It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.

References (25)

Core 25
Core References
Vendor Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2016-2035.html
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1345
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1376
Vendor Advisory vendor-advisory
https://rhn.redhat.com/errata/RHSA-2016-1330.html
Vendor Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2016-1439.html
Broken Link, Vendor Advisory vendor-advisory
https://rhn.redhat.com/errata/RHSA-2016-1331.html
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1434
Vendor Advisory vendor-advisory
https://rhn.redhat.com/errata/RHSA-2016-1328.html
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1433
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1374
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1432
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1346
Vendor Advisory vendor-advisory
https://rhn.redhat.com/errata/RHSA-2016-1334.html
Broken Link, Vendor Advisory vendor-advisory
https://rhn.redhat.com/errata/RHSA-2016-1333.html
Broken Link, Vendor Advisory vendor-advisory
https://rhn.redhat.com/errata/RHSA-2016-1329.html
Vendor Advisory vendor-advisory
https://rhn.redhat.com/errata/RHSA-2016-1332.html
Vendor Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2016-1435.html
Broken Link, Third Party Advisory, VDB Entry vdb-entry
http://www.securitytracker.com/id/1036165
Issue Tracking, Vendor Advisory
https://issues.jboss.org/browse/JGRP-2021
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1347
Vendor Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2016:1389

Scores

CVSS v3 9.8
EPSS 0.0470
EPSS Percentile 90.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (5)
org.jgroups/jgroups 3.3.0.Alpha1 - 3.6.10.FinalMaven
redhat/jboss_enterprise_application_platform 5.2
redhat/jboss_enterprise_application_platform 6.4
redhat/jboss_enterprise_application_platform 7.0
redhat/jgroups < 4.0
Published Jun 30, 2016
Tracked Since Feb 18, 2026