CVE-2022-32531

MEDIUM

Apache Bookkeeper < 4.14.6 - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails. This leaves the bookkeeper client vulnerable to a man in the middle attack. The problem affects BookKeeper client prior to versions 4.14.6 and 4.15.1.

References (1)

Core 1
Core References
Mailing List, Vendor Advisory vendor-advisory
https://lists.apache.org/thread/xyk2lfc7lzof8mksmwyympbqxts1b5s9

Scores

CVSS v3 5.9
EPSS 0.0080
EPSS Percentile 74.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (3)
apache/bookkeeper 4.15.0 (2 CPE variants)
apache/bookkeeper < 4.14.6
org.apache.bookkeeper/bookkeeper-common 0 - 4.14.6Maven
Published Dec 15, 2022
Tracked Since Feb 18, 2026