Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vh98-fqfc-4hj3

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Apache Geode vulnerable to Exposure of Sensitive Information

When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could leak information about application data types. In addition, an attacker could perform a denial of service attack on the cluster.

Пакеты

Наименование

org.apache.geode:geode-core

maven
Затронутые версииВерсия исправления

>= 1.0.0, < 1.2.1

1.2.1

EPSS

Процентиль: 57%
0.00345
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
nvd
больше 8 лет назад

When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could leak information about application data types. In addition, an attacker could perform a denial of service attack on the cluster.

EPSS

Процентиль: 57%
0.00345
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200