Vulnerability Description
When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could leak information about application data types. In addition, an attacker could perform a denial of service attack on the cluster.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Geode | <= 1.2.0 |
Related Weaknesses (CWE)
References
- http://mail-archives.apache.org/mod_mbox/geode-user/201709.mbox/%3cCAEwge-Hrbb7J
- http://mail-archives.apache.org/mod_mbox/geode-user/201709.mbox/%3cCAEwge-Hrbb7J
FAQ
What is CVE-2017-9797?
CVE-2017-9797 is a vulnerability with a CVSS score of 6.5 (MEDIUM). When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could l...
How severe is CVE-2017-9797?
CVE-2017-9797 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9797?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Geode.