VYPR

Geode

by Apache

Source repositories

CVEs (23)

  • CVE-2017-15693HigFeb 27, 2018
    risk 0.00cvss 7.5epss 0.02

    In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objects to be deserialized. A user with DATA:WRITE access to the cluster may be able to cause remote code execution if…

  • CVE-2017-15692CriFeb 27, 2018
    risk 0.00cvss 9.8epss 0.05

    In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they may be able to cause remote code execution if certain classes are present on the classpath.

  • CVE-2017-15696HigFeb 26, 2018
    risk 0.00cvss 7.5epss 0.02

    When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains access to the Geode locator to extract configuration data and previously…

Page 2 of 2