Vulnerability Description
When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains access to the Geode locator to extract configuration data and previously deployed application code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Geode | >= 1.0.0, <= 1.3.0 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/28989e6ed0d3c29e46a489ae508302a50407a40691d
- https://lists.apache.org/thread.html/28989e6ed0d3c29e46a489ae508302a50407a40691d
FAQ
What is CVE-2017-15696?
CVE-2017-15696 is a vulnerability with a CVSS score of 7.5 (HIGH). When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains a...
How severe is CVE-2017-15696?
CVE-2017-15696 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15696?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Geode.