PT-2021-11727 · Atomix · Atomix

Published

2021-12-16

·

Updated

2021-12-21

·

CVE-2020-35211

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Atomix version 3.1.5
Description: The issue allows unauthorized Atomix nodes to become the lead node in a target cluster. This is achieved through manipulation of the terms variable in RaftContext.
Recommendations: For Atomix version 3.1.5, consider restricting access to the RaftContext to prevent unauthorized nodes from manipulating the terms variable until a patch is available. As a temporary workaround, monitor cluster activity closely to detect and respond to potential unauthorized lead node elections. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-35211
GHSA-4JHC-WJR3-PWH2

Affected Products

Atomix