CVE-2016-2141: Input Validation
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
Other sources
JGroups before 4.0 does not require the proper headers for the ENCRYPT and AUTH protocols from nodes joining the cluster, which allows remote attackers to bypass security restrictions and send and receive messages within the cluster via unspecified vectors. Fixes for this issue have been backported to versions 3.6.10.Final and 3.2.16.Final.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.jgroups:jgroupsto a version that resolves this vulnerability.Fixed in 3.2.16.Final - Upgrade
Upgrade
maven/org.jgroups:jgroupsto a version that resolves this vulnerability.Fixed in 3.6.10.Final - Upgrade
Upgrade
redhat/jgroupsto a version that resolves this vulnerability.Fixed in 3.6.10. - Upgrade
Upgrade
JGroupsto a version that resolves this vulnerability.Fixed in 3.6.10.Final - Upgrade
Upgrade
JGroupsto a version that resolves this vulnerability.Fixed in 3.2.16.Final
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2141?
CVE-2016-2141 is classified as a moderate severity vulnerability.
How do I fix CVE-2016-2141?
To resolve CVE-2016-2141, upgrade to JGroups version 3.2.16.Final or 3.6.10.Final or later.
What software is affected by CVE-2016-2141?
CVE-2016-2141 affects JGroups versions prior to 3.2.16.Final and versions between 3.3.0.Alpha1 and 3.6.10.Final.
What type of attack can be executed with CVE-2016-2141?
An attacker can exploit CVE-2016-2141 to bypass security measures and send and receive messages within an affected JGroups cluster.
Is there a specific configuration that can mitigate CVE-2016-2141?
There is no specific configuration to mitigate CVE-2016-2141; the recommended action is to upgrade to a secure version.