www-announce mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Anthony Baker <aba...@apache.org>
Subject [SECURITY] CVE-2017-15695 Apache Geode remote code execution vulnerability
Date Tue, 12 Jun 2018 21:14:25 GMT
CVE-2017-15695 Apache Geode remote code execution vulnerability

Severity:  Important

Vendor: The Apache Software Foundation

Versions Affected:  Apache Geode 1.0.0 through 1.4.0

Description:
When a Geode server is configured with a security manager, a user with
DATA:WRITE privileges is allowed to deploy code by invoking an
internal Geode function.  This allows remote code execution.  Code
deployment should be restricted to users with DATA:MANAGE privilege.

Mitigation:
Users of the affected versions should upgrade to Apache Geode 1.5.0 or later.

Credit:
This issue was reported responsibly to the Apache Geode Security Team
by Dan Smith from Pivotal Software.

References:
[1] https://issues.apache.org/jira/browse/GEODE-3974
[2] https://cwiki.apache.org/confluence/display/GEODE/Release+Notes#ReleaseNotes-SecurityVulnerabilities

Mime
View raw message