DescriptionJGroups before 4.0 does not require the proper headers for the ENCRYPT and AUTH protocols from nodes joining the cluster, which allows remote attackers to bypass security restrictions and send and receive messages within the cluster via unspecified vectors.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh (attack range: remote)
Debian Bugs867493

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libjgroups-java (PTS)jessie, stretch2.12.2.Final-4vulnerable
buster, sid2.12.2.Final-5vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs


[buster] - libjgroups-java <ignored> (Minor issue, only used as build dep)
[stretch] - libjgroups-java <ignored> (Minor issue, only used as build dep)
[jessie] - libjgroups-java <no-dsa> (Minor issue)
[wheezy] - libjgroups-java <no-dsa> (Minor issue, only used as build dependency)

