You are viewing a plain text version of this content. The canonical link for it is here.
Posted to user@geode.apache.org by Anthony Baker <ab...@apache.org> on 2019/06/20 14:22:18 UTC

[CVE-2017-15694] Apache Geode metadata modification vulnerability

CVE-2017-15694 Apache Geode metadata modification vulnerability

Severity: Medium

Vendor: The Apache Software Foundation

Versions Affected:
Apache Geode 1.0.0 through 1.8.0

Description:
When a Geode server is operating in secure mode, a user with write
permissions for specific data regions can modify internal cluster
metadata.  A malicious user could modify this data in a way that affects
the operation of the cluster.

Mitigation:
Users of the affected versions should upgrade to Apache Geode 1.9.0 or
later.

Credit:
This issue was reported responsibly to the Apache Geode Security Team by
Jason Huynh from Pivotal.

References:
[1] https://issues.apache.org/jira/browse/GEODE-3981
[2]
https://cwiki.apache.org/confluence/display/GEODE/Release+Notes#ReleaseNotes-SecurityVulnerabilities

---
The Geode PMC