VYPR
Moderate severityNVD Advisory· Published Dec 15, 2022· Updated Apr 17, 2025

Apache BookKeeper: Java Client Uses Connection to Host that Failed Hostname Verification

CVE-2022-32531

Description

The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails. This leaves the bookkeeper client vulnerable to a man in the middle attack.

The problem affects BookKeeper client prior to versions 4.14.6 and 4.15.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.bookkeeper:bookkeeper-commonMaven
< 4.14.64.14.6
org.apache.bookkeeper:bookkeeper-commonMaven
>= 4.15.0, < 4.15.14.15.1

Affected products

2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.