You are viewing a plain text version of this content. The canonical link for it is here.
Posted to user@geode.apache.org by Anthony Baker <ab...@apache.org> on 2020/03/14 00:28:26 UTC
[CVE-2019-10091] Apache Geode SSL endpoint verification vulnerability
CVE-2019-10091 Apache Geode SSL endpoint verification vulnerability
Severity: Medium
Vendor: The Apache Software Foundation
Versions Affected:
Apache Geode 1.9.0
Description:
When TLS is enabled with ssl-endpoint-identification-enabled set to
true, Apache Geode fails to perform hostname verification of the
entries in the certificate SAN during the SSL handshake. This could
compromise intra-cluster communication using a man-in-the-middle
attack.
Mitigation:
Users of the affected versions should upgrade to Apache Geode 1.9.1,
1.10.0, or later.
Credit:
This issue was reported responsibly to the Apache Geode Security Team
by Sai Boorlagadda from Pivotal.
References:
[1] https://issues.apache.org/jira/browse/GEODE-7018
[2] https://cwiki.apache.org/confluence/display/GEODE/Release+Notes#ReleaseNotes-SecurityVulnerabilities