Количество 2
Количество 2
CVE-2019-10091
When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a man-in-the-middle attack.
GHSA-wc4x-4gm2-74j8
Apache Geode SSL endpoint verification vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-10091 When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a man-in-the-middle attack. | CVSS3: 7.4 | 0% Низкий | почти 6 лет назад | |
GHSA-wc4x-4gm2-74j8 Apache Geode SSL endpoint verification vulnerability | CVSS3: 7.4 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу