Description
An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to become the lead node in a target cluster via manipulation of the variable terms in RaftContext.
Remediation
References
https://docs.google.com/presentation/d/1C_IpRfSU-9FMezcHCFZ-qg-15JO-W36yvqcnzI8sQs8/edit?usp=sharing
Related Vulnerabilities
CVE-2023-37951 Vulnerability in maven package com.mabl.integration.jenkins:mabl-integration
CVE-2021-41182 Vulnerability in maven package org.webjars.bower:jquery-ui
CVE-2022-40955 Vulnerability in maven package org.apache.inlong:manager-pojo
CVE-2022-25873 Vulnerability in npm package vuetify
CVE-2021-40111 Vulnerability in maven package org.apache.james:james-server