Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g569-49wg-jx5f

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Apache Geode configuration request authorization vulnerability

When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains access to the Geode locator to extract configuration data and previously deployed application code.

Пакеты

Наименование

org.apache.geode:geode-core

maven
Затронутые версииВерсия исправления

>= 1.0.0, < 1.4.0

1.4.0

EPSS

Процентиль: 69%
0.00609
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
nvd
почти 8 лет назад

When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains access to the Geode locator to extract configuration data and previously deployed application code.

EPSS

Процентиль: 69%
0.00609
Низкий

7.5 High

CVSS3

Дефекты

CWE-200