Description
An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to become the lead node in a target cluster via manipulation of the variable terms in RaftContext.
Remediation
References
https://docs.google.com/presentation/d/1C_IpRfSU-9FMezcHCFZ-qg-15JO-W36yvqcnzI8sQs8/edit?usp=sharing
Related Vulnerabilities
CVE-2020-10991 Vulnerability in maven package org.mule.modules:mule-module-apikit
CVE-2024-36401 Vulnerability in maven package org.geoserver:gs-wfs
CVE-2022-41854 Vulnerability in maven package org.yaml:snakeyaml
CVE-2021-23436 Vulnerability in npm package immer
CVE-2021-23664 Vulnerability in npm package @isomorphic-git/cors-proxy