Lucene search

K
githubGitHub Advisory DatabaseGHSA-QF8G-VPWP-6579
HistorySep 01, 2022 - 12:00 a.m.

Apache Geode versions deserialization of untrusted datawhen using JMX over RMI on Java 11

2022-09-0100:00:26
CWE-502
GitHub Advisory Database
github.com
18
apache geode
deserialization
jmx over rmi
java 11
upgrade
vulnerability
gfsh
communication

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

68.4%

Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user wishing to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode 1.15. Use of 1.15 on Java 11 will automatically protect JMX over RMI against deserialization attacks. This should have no impact on performance since it only affects JMX/RMI which Gfsh uses to communicate with the JMX Manager which is hosted on a Locator.

Affected configurations

Vulners
Node
org.apache.geodegeode-coreRange<1.15.0
VendorProductVersionCPE
org.apache.geodegeode-core*cpe:2.3:a:org.apache.geode:geode-core:*:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

68.4%

Related for GHSA-QF8G-VPWP-6579