|
Message-ID: <CACcefgfgnn7assSeTVLMaXDWuduiE=qxhFLx5NM_NtcKNVeYpA@mail.gmail.com> Date: Thu, 15 Dec 2022 10:14:15 +0100 From: Enrico Olivelli <eolivelli@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2022-32531: Apache BookKeeper: Java Client Uses Connection to Host that Failed Hostname Verification Severity: Moderate Description: The Apache Bookkeeper Java Client (up to 4.14.5 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails. This leaves the bookkeeper client vulnerable to a man in the middle attack. The problem affects BookKeeper client prior to versions 4.14.6 and 4.15.1. Solution: Upgrade to 4.14.6 or to 4.15.1 References: https://bookkeeper.apache.org/ https://www.cve.org/CVERecord?id=CVE-2022-32531
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.