Description
JGroups before 4.0 does not require the proper headers for the ENCRYPT and AUTH protocols from nodes joining the cluster, which allows remote attackers to bypass security restrictions and send and receive messages within the cluster via unspecified vectors.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2614 Vulnerability (CVE-2019-2614)
Oracle Database Server CVE-2014-4289 Vulnerability (CVE-2014-4289)
WordPress Plugin WooCommerce PayPal Checkout Payment Gateway Parameter Tampering (1.6.8)
WordPress Plugin 2 Click Social Media Buttons 'xing-url' Parameter Cross-Site Scripting (0.32.2)