Description
An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to join a target cluster via providing configuration information.
Remediation
References
https://docs.google.com/presentation/d/1W5KU7ffh4dheR8iD54ulABImi6byAhSI-OhEKw2adRo/edit?usp=sharing
Related Vulnerabilities
CVE-2021-23700 Vulnerability in npm package merge-deep2
CVE-2019-16548 Vulnerability in maven package org.jenkins-ci.plugins:google-compute-engine
CVE-2022-39366 Vulnerability in maven package io.acryl:datahub-client
CVE-2022-31103 Vulnerability in npm package lettersanitizer
CVE-2017-5662 Vulnerability in maven package batik:batik-dom