Argument Injection in Apache Geode server
Moderate severity
GitHub Reviewed
Published
Jun 26, 2019
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Jun 21, 2019
Reviewed
Jun 26, 2019
Published to the GitHub Advisory Database
Jun 26, 2019
Last updated
Feb 1, 2023
When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cluster metadata. A malicious user could modify this data in a way that affects the operation of the cluster.
References