Lucene search

K
osvGoogleOSV:GHSA-G569-49WG-JX5F
HistoryMay 14, 2022 - 3:37 a.m.

Apache Geode configuration request authorization vulnerability

2022-05-1403:37:08
Google
osv.dev
7
apache geode
configuration
authorization
vulnerability
secure mode
unprivileged user
geode locator
configuration data
application code

EPSS

0.001

Percentile

30.0%

When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains access to the Geode locator to extract configuration data and previously deployed application code.

EPSS

0.001

Percentile

30.0%

Related for OSV:GHSA-G569-49WG-JX5F