REDHAT-BUG-983489: Low severity JGroups JGroups vulnerability
A flaw was found in JGroup's DiagnosticsHandler that allowed an attacker on an adjacent network to reuse the credentials from a previous successful authentication. This could be exploited to read diagnostic information (information disclosure) and attain limited remote code execution.
This issue affects JGroups versions 3.0.x (3.0.11.Final and later), 3.1.x (3.1.0.Final and later), 3.2.x (prior to 3.2.10.Final) and 3.3.x (prior to 3.3.3.Final).
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-983489?
The severity of REDHAT-BUG-983489 is considered critical due to its potential for information disclosure and limited remote code execution.
How do I fix REDHAT-BUG-983489?
To fix REDHAT-BUG-983489, update JGroups to a version that is not affected by this vulnerability, specifically versions 3.2.10.Final or later.
What versions of JGroups are affected by REDHAT-BUG-983489?
REDHAT-BUG-983489 affects JGroups versions from 3.0.11.Final up to but not including 3.3.3.Final.
What are the potential impacts of exploiting REDHAT-BUG-983489?
Exploiting REDHAT-BUG-983489 could lead to unauthorized reading of diagnostic information and possible limited remote code execution.
Who is vulnerable to REDHAT-BUG-983489?
Systems running the affected versions of JGroups are vulnerable to REDHAT-BUG-983489, particularly those in an adjacent network.