Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12068
HistoryJan 15, 2019 - 9:11 a.m.

Authorization Bypass

2019-01-1509:11:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.007 Low

EPSS

Percentile

79.5%

JGroup is vulnerable to aurthorization bypass attacks which can lead to information disclosure and spoofing attacks. The vulnerability exists as a malicious user can bypass security restrictions when the attacker node joins the cluster. It happens as JGroup did not check for the essential headers for encrypt and auth protocols when a new node joins the cluster.

References