Description
When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In Apache Geode before 1.2.1, the query results may contain data from another user's concurrently executing gfsh query, potentially revealing data that the user is not authorized to view.
References (1)
Core 1
Core References
Various Sources mailing-list
x_refsource_mlist
http://mail-archives.apache.org/mod_mbox/geode-user/201709.mbox/%3cCAEwge-FqzrT+deCkNkM-EQZuKfg-XuqY4cGjFiqxoKBVduY1Zw%40mail.gmail.com%3e
Scores
CVSS v3
4.3
EPSS
0.0013
EPSS Percentile
31.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (6)
apache/geode
< 1.2.0
Apache Software Foundation/Apache Geode
1.0.0
Apache Software Foundation/Apache Geode
1.1.0
Apache Software Foundation/Apache Geode
1.1.1
Apache Software Foundation/Apache Geode
1.2.0
org.apache.geode/geode-core
1.0.0 - 1.2.1Maven
Published
Sep 30, 2017
Tracked Since
Feb 18, 2026