Количество 2
Количество 2
CVE-2017-15693
In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objects to be deserialized. A user with DATA:WRITE access to the cluster may be able to cause remote code execution if certain classes are present on the classpath.
GHSA-95m2-p98f-24r5
Apache Geode unsafe deserialization of application objects
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2017-15693 In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objects to be deserialized. A user with DATA:WRITE access to the cluster may be able to cause remote code execution if certain classes are present on the classpath. | CVSS3: 7.5 | 2% Низкий | почти 8 лет назад | |
GHSA-95m2-p98f-24r5 Apache Geode unsafe deserialization of application objects | CVSS3: 7.5 | 2% Низкий | больше 3 лет назад |
Уязвимостей на страницу