Описание
Argument Injection in Apache Geode server
When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cluster metadata. A malicious user could modify this data in a way that affects the operation of the cluster.
Пакеты
Наименование
org.apache.geode:geode-core
maven
Затронутые версииВерсия исправления
< 1.9.0
1.9.0
Связанные уязвимости
CVSS3: 6.5
nvd
больше 6 лет назад
When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cluster metadata. A malicious user could modify this data in a way that affects the operation of the cluster.