Apache Geode vulnerable to Incorrect Authorization
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Apr 12, 2024
Package
Affected versions
>= 1.0.0, < 1.5.0
Patched versions
1.5.0
Description
Published by the National Vulnerability Database
Jun 13, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Nov 8, 2022
Last updated
Apr 12, 2024
When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode function. This allows remote code execution. Code deployment should be restricted to users with DATA:MANAGE privilege.
References