Description
When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cluster metadata. A malicious user could modify this data in a way that affects the operation of the cluster.
References (2)
Core 2
Core References
Mailing List x_refsource_misc
https://lists.apache.org/thread.html/311505e7b7a045aaa246f0a1935703acacf41b954621b1363c40bf6f%40%3Cuser.geode.apache.org%3E
Third Party Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/108870
Scores
CVSS v3
6.5
EPSS
0.0071
EPSS Percentile
72.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-88
Status
published
Products (2)
apache/geode
1.0.0 - 1.8.0
org.apache.geode/geode-core
0 - 1.9.0Maven
Published
Jun 21, 2019
Tracked Since
Feb 18, 2026