Описание
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries that allow read and write access to objects within unauthorized regions. In addition a user could invoke methods that allow remote code execution.
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.0 (исключая)
cpe:2.3:a:apache:geode:*:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.0263
Низкий
7.5 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
Apache Geode OQL method invocation vulnerability
EPSS
Процентиль: 85%
0.0263
Низкий
7.5 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-200