Vulnerabilities > Apache > Geode > High

DATE CVE VULNERABILITY TITLE RISK
2022-08-31 CVE-2022-37022 Deserialization of Untrusted Data vulnerability in Apache Geode
Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11.
network
low complexity
apache CWE-502
8.8
2022-01-04 CVE-2021-34797 Information Exposure Through Log Files vulnerability in Apache Geode
Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "javax.net.ssl", or "security-".
network
low complexity
apache CWE-532
7.5
2020-03-16 CVE-2019-10091 Improper Certificate Validation vulnerability in Apache Geode 1.9.0
When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake.
network
high complexity
apache CWE-295
7.4
2019-08-28 CVE-2019-15752 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.
local
low complexity
docker apache CWE-732
7.8
2018-06-13 CVE-2017-15695 Incorrect Authorization vulnerability in Apache Geode
When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode function.
network
low complexity
apache CWE-863
8.8
2018-02-27 CVE-2017-15693 Deserialization of Untrusted Data vulnerability in Apache Geode
In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form.
network
high complexity
apache CWE-502
7.5
2018-02-26 CVE-2017-15696 Information Exposure vulnerability in Apache Geode
When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests.
network
low complexity
apache CWE-200
7.5
2018-01-10 CVE-2017-9795 Information Exposure vulnerability in Apache Geode
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries that allow read and write access to objects within unauthorized regions.
network
high complexity
apache CWE-200
7.5
2018-01-10 CVE-2017-12622 Information Exposure vulnerability in Apache Geode
When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status information and control cluster members even without CLUSTER:MANAGE privileges.
network
low complexity
apache CWE-200
7.1
2017-04-04 CVE-2017-5649 Information Exposure vulnerability in Apache Geode 1.0.0/1.1.0
Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ but not DATA:READ permission to access the data browser page in Pulse and consequently execute an OQL query that exposes data stored in the cluster.
network
low complexity
apache CWE-200
7.5