Description
An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to become the lead node in a target cluster via manipulation of the variable terms in RaftContext.
Remediation
References
https://docs.google.com/presentation/d/1C_IpRfSU-9FMezcHCFZ-qg-15JO-W36yvqcnzI8sQs8/edit?usp=sharing
Related Vulnerabilities
CVE-2017-16094 Vulnerability in npm package iter-http
CVE-2014-9772 Vulnerability in npm package validator
CVE-2016-7103 Vulnerability in maven package org.fujion.webjars:jquery-ui
CVE-2018-1000616 Vulnerability in maven package org.onosproject:onos-cli
CVE-2020-28052 Vulnerability in maven package org.bouncycastle:bcprov-debug-jdk15on