You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@geode.apache.org by Anthony Baker <ab...@apache.org> on 2018/01/09 22:07:14 UTC
[SECURITY] CVE-2017-12622 Apache Geode gfsh authorization vulnerability
CVE-2017-12622 Apache Geode gfsh authorization vulnerability
Severity: Important
Vendor: The Apache Software Foundation
Versions Affected: Apache Geode 1.0.0 through 1.2.1
Description:
When an authenticated user connects to a Geode cluster using the gfsh
tool with HTTP, the user is able to obtain status information and
control cluster members even without CLUSTER:MANAGE privileges.
Mitigation:
Users of the affected versions should upgrade to Apache Geode 1.3.0 or later.
Credit:
This issue was reported responsibly to the Apache Geode Security Team
by Patrick Rhomberg from Pivotal.
References:
[1] https://issues.apache.org/jira/browse/GEODE-3685
[2] https://cwiki.apache.org/confluence/display/GEODE/Release+Notes#ReleaseNotes-SecurityVulnerabilities
---
The Geode PMC