GHSA-vh98-fqfc-4hj3
Dashboard / Vulnerabilities / GHSA-vh98-fqfc-4hj3
Summary: Apache Geode vulnerable to Exposure of Sensitive Information
Details: When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could leak information about application data types. In addition, an attacker could perform a denial of service attack on the cluster.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-9797, https://cwiki.apache.org/confluence/display/GEODE/Release+Notes#ReleaseNotes-SecurityVulnerabilities, https://issues.apache.org/jira/browse/GEODE-3249, http://mail-archives.apache.org/mod_mbox/geode-user/201709.mbox/%3cCAEwge-Hrbb7JS8Nygrh7geyFvW4bMZ3AdCmPOzMfvbniipz0bA@mail.gmail.com%3e
Affected packages
Package
Name: org.apache.geode:geode-core
Purl: pkg:maven/org.apache.geode/geode-core
Affected ranges
Type: ECOSYSTEM
Events:
