CVE-2017-5649

HIGH

Apache Geode < 1.1.1 - Authenticated Sensitive Data Exposure via Pulse Data Browser

Title source: llm
STIX 2.1

Description

Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ but not DATA:READ permission to access the data browser page in Pulse and consequently execute an OQL query that exposes data stored in the cluster.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97378

Scores

CVSS v3 7.5
EPSS 0.0007
EPSS Percentile 22.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (3)
apache/geode < 1.1.0
Apache Software Foundation/Apache Geode 1.1.0
org.apache.geode/geode-core 1.1.0 - 1.1.1Maven
Published Apr 04, 2017
Tracked Since Feb 18, 2026