CVE-2017-15696: Infoleak
Published Feb 26, 2018
·Updated
When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains access to the Geode locator to extract configuration data and previously deployed application code.
Affected Software
1 affected component
Apache Geode>=1.0.0<=1.3.0
Event History
Feb 26, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this Apache Geode vulnerability?
The vulnerability ID is CVE-2017-15696.
2
What is the severity of CVE-2017-15696?
The severity of CVE-2017-15696 is high with a severity value of 7.5.
3
How does CVE-2017-15696 affect Apache Geode?
CVE-2017-15696 affects Apache Geode versions before v1.4.0 operating in secure mode.
4
What is the impact of CVE-2017-15696?
CVE-2017-15696 allows an unprivileged user who gains access to the Geode locator to extract configuration data and previously deployed application code.
5
Is there a fix for CVE-2017-15696?
Yes, upgrading to Apache Geode v1.4.0 or later fixes CVE-2017-15696.