Description
JGroups before 4.0 does not require the proper headers for the ENCRYPT and AUTH protocols from nodes joining the cluster, which allows remote attackers to bypass security restrictions and send and receive messages within the cluster via unspecified vectors.
Remediation
References
Related Vulnerabilities
WordPress 3.9.x Multiple Vulnerabilities (3.9 - 3.9.12)
WordPress Plugin WP Super Cache Remote Code Execution (1.7.1)
WordPress Plugin WP Maps-Display Google Maps Perfectly with Ease Unspecified Vulnerability (3.1.6)
WordPress Plugin Codestyling Localization 'name' Parameter Cross-Site Scripting (1.99.19)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5731)