← Back to CVE List

CVE-2022-32531

Published: 2022-12-15T19:15Z
Last Modified: 2024-11-21T07:06Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails. This leaves the bookkeeper client vulnerable to a man in the middle attack. The problem affects BookKeeper client prior to versions 4.14.6 and 4.15.1. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt