CVE-2017-15694: Medium severity apache geode vulnerability
When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cluster metadata. A malicious user could modify this data in a way that affects the operation of the cluster.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-15694?
CVE-2017-15694 is a vulnerability in Apache Geode server versions 1.0.0 to 1.8.0 that allows a user to modify internal cluster metadata when operating in secure mode.
What is the severity of CVE-2017-15694?
CVE-2017-15694 has a severity rating of 6.5, which is considered medium.
How does CVE-2017-15694 affect Apache Geode server?
CVE-2017-15694 allows a user with write permissions for specific data regions to modify internal cluster metadata, potentially affecting the operation of the cluster.
What software versions are affected by CVE-2017-15694?
Apache Geode server versions 1.0.0 to 1.8.0 are affected by CVE-2017-15694.
How can CVE-2017-15694 be fixed?
There is currently no known fix for CVE-2017-15694. It is recommended to update to a version of Apache Geode server that is not affected by this vulnerability when it becomes available.