5.9
CVE-2022-32531
- EPSS 0.14%
- Veröffentlicht 15.12.2022 19:15:17
- Zuletzt bearbeitet 17.04.2025 19:15:53
- Quelle security@apache.org
- Teams Watchlist Login
- Unerledigt Login
The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails. This leaves the bookkeeper client vulnerable to a man in the middle attack. The problem affects BookKeeper client prior to versions 4.14.6 and 4.15.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Bookkeeper Version < 4.14.6
Apache ≫ Bookkeeper Version4.15.0 Update-
Apache ≫ Bookkeeper Version4.15.0 Updaterc0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.14% | 0.354 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.