First published: Tue Jan 09 2018(Updated: )
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind parameter that allow read access to objects within unauthorized regions.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Geode | <1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9796 is a vulnerability in Apache Geode that allows a user with read access to specific regions within a Geode cluster to execute OQL queries containing a region name as a bind parameter that allow read access to objects within unauthorized regions.
CVE-2017-9796 has a severity rating of 5.3 (medium).
Apache Geode versions up to but excluding v1.3.0 are affected by CVE-2017-9796.
CVE-2017-9796 is associated with CWE-200.
Yes, you can find more information about CVE-2017-9796 at the following link: [Apache Geode Mailing List](https://lists.apache.org/thread.html/e580d22195b6b61ff9cf866ac6dd6fe16e790ff0e14a3b1a22cd20b1@%3Cuser.geode.apache.org%3E)