CVE-2017-9796: Infoleak
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind parameter that allow read access to objects within unauthorized regions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-9796?
CVE-2017-9796 is a vulnerability in Apache Geode that allows a user with read access to specific regions within a Geode cluster to execute OQL queries containing a region name as a bind parameter that allow read access to objects within unauthorized regions.
How severe is CVE-2017-9796?
CVE-2017-9796 has a severity rating of 5.3 (medium).
Which version of Apache Geode is affected by CVE-2017-9796?
Apache Geode versions up to but excluding v1.3.0 are affected by CVE-2017-9796.
What is the Common Weakness Enumeration (CWE) associated with CVE-2017-9796?
CVE-2017-9796 is associated with CWE-200.
Are there any references or resources available for CVE-2017-9796?
Yes, you can find more information about CVE-2017-9796 at the following link: [Apache Geode Mailing List](https://lists.apache.org/thread.html/e580d22195b6b61ff9cf866ac6dd6fe16e790ff0e14a3b1a22cd20b1@%3Cuser.geode.apache.org%3E)