When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind parameter that allow read access to objects within unauthorized regions.
References
Link | Resource |
---|---|
https://lists.apache.org/thread.html/e580d22195b6b61ff9cf866ac6dd6fe16e790ff0e14a3b1a22cd20b1@%3Cuser.geode.apache.org%3E | Mailing List Vendor Advisory |
Configurations
Information
Published : 2018-01-09 19:29
Updated : 2018-02-02 07:56
NVD link : CVE-2017-9796
Mitre link : CVE-2017-9796
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
apache
- geode