Moderate severityNVD Advisory· Published Dec 15, 2022· Updated Apr 17, 2025
Apache BookKeeper: Java Client Uses Connection to Host that Failed Hostname Verification
CVE-2022-32531
Description
The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails. This leaves the bookkeeper client vulnerable to a man in the middle attack.
The problem affects BookKeeper client prior to versions 4.14.6 and 4.15.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.bookkeeper:bookkeeper-commonMaven | < 4.14.6 | 4.14.6 |
org.apache.bookkeeper:bookkeeper-commonMaven | >= 4.15.0, < 4.15.1 | 4.15.1 |
Affected products
2- Range: 0
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.