Back

MEDIUM

JON: Unapproved agents can connect using the name of an existing approved agent

Published Feb 14, 2014

Description

Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof the identity of arbitrary agents via the registered agent name.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 14, 2014
Updated Aug 6, 2024
Reserved Dec 7, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Feb 1, 2012