Description
An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to become the lead node in a target cluster via manipulation of the variable terms in RaftContext.
Remediation
References
https://docs.google.com/presentation/d/1C_IpRfSU-9FMezcHCFZ-qg-15JO-W36yvqcnzI8sQs8/edit?usp=sharing
Related Vulnerabilities
CVE-2022-0776 Vulnerability in npm package reveal.js
CVE-2022-45210 Vulnerability in maven package org.jeecgframework.boot:jeecg-module-system
CVE-2021-32819 Vulnerability in npm package squirrelly
CVE-2015-8315 Vulnerability in npm package ms
CVE-2020-7760 Vulnerability in maven package org.webjars.bowergithub.codemirror:codemirror