[MAVEN:GHSA-P426-QW2P-V95V] Argument Injection in Apache Geode server

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cluster metadata. A malicious user could modify this data in a way that affects the operation of the cluster.

Package Affected Version
pkg:maven/org.apache.geode/geode-core < 1.9.0
Package Fixed Version
pkg:maven/org.apache.geode/geode-core = 1.9.0
ID
MAVEN:GHSA-P426-QW2P-V95V
Severity
moderate
URL
https://github.com/advisories/GHSA-p426-qw2p-v95v
Published
2019-06-26T01:09:35
(5 years ago)
Modified
2023-02-01T05:02:21
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.geode/geode-core org.apache.geode geode-core < 1.9.0
Fixed pkg:maven/org.apache.geode/geode-core org.apache.geode geode-core = 1.9.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...