CVE-2022-32531
Last modified
CVE-2022-32531 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails. This leaves the bookkeeper client vulnerable to a man in the middle attack. The problem affects BookKeeper client prior to versions 4.14.6 and 4.15.1.. EPSS estimates a 1.02% chance of exploitation in the next 30 days.
Description
The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails. This leaves the bookkeeper client vulnerable to a man in the middle attack. The problem affects BookKeeper client prior to versions 4.14.6 and 4.15.1.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Bookkeeper | < 4.14.6 |
| Apache | Bookkeeper | 4.15.0 |
References
- https://lists.apache.org/thread/xyk2lfc7lzof8mksmwyympbqxts1b5s9Mailing List, Vendor Advisory
- https://lists.apache.org/thread/xyk2lfc7lzof8mksmwyympbqxts1b5s9Mailing List, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-32531?
How severe is CVE-2022-32531?
How do I fix CVE-2022-32531?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-32525A CWE-120: Buffer Copy without Checking Size of Input vulner…9.8
- CVE-2022-32526A CWE-120: Buffer Copy without Checking Size of Input vulner…9.8
- CVE-2022-32527A CWE-120: Buffer Copy without Checking Size of Input vulner…9.8
- CVE-2022-32528 A CWE-306: Missing Authentication for Critical Function vul…9.1
- CVE-2022-32529A CWE-120: Buffer Copy without Checking Size of Input vulner…9.8
- CVE-2022-32530A CWE-668 Exposure of Resource to Wrong Sphere vulnerability…7.8
- CVE-2022-32532Apache Shiro before 1.9.1, A RegexRequestMatcher can be misc…9.8
- CVE-2022-32533Apache Jetspeed-2 does not sufficiently filter untrusted use…9.8
- CVE-2022-32534The Bosch Ethernet switch PRA-ES8P2S with software version 1…9.8
- CVE-2022-32535The Bosch Ethernet switch PRA-ES8P2S with software version 1…9.8
- CVE-2022-32536The user access rights validation in the web server of the B…8.8
- CVE-2022-32537A vulnerability exists which could allow an unauthorized use…4.8
Are you affected by CVE-2022-32531?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
