Medium severity5.9NVD Advisory· Published Dec 15, 2022· Updated Jun 17, 2026
CVE-2022-32531
CVE-2022-32531
Description
The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails. This leaves the bookkeeper client vulnerable to a man in the middle attack.
The problem affects BookKeeper client prior to versions 4.14.6 and 4.15.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.bookkeeper:bookkeeper-commonMaven | < 4.14.6 | 4.14.6 |
org.apache.bookkeeper:bookkeeper-commonMaven | >= 4.15.0, < 4.15.1 | 4.15.1 |
Affected products
5cpe:2.3:a:apache:bookkeeper:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:apache:bookkeeper:*:*:*:*:*:*:*:*range: <4.14.6
- cpe:2.3:a:apache:bookkeeper:4.15.0:-:*:*:*:*:*:*
- cpe:2.3:a:apache:bookkeeper:4.15.0:rc0:*:*:*:*:*:*
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-gxq5-79m2-gvvqghsaADVISORY
- lists.apache.org/thread/xyk2lfc7lzof8mksmwyympbqxts1b5s9nvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-32531ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/apache-bookkeeper-client/PYSEC-2022-43060.yamlghsaWEB
News mentions
0No linked articles in our index yet.