CVE-2017-12622

Severity
7.1HIGH
EPSS
0.1%
top 76.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateMay 14

Description

When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status information and control cluster members even without CLUSTER:MANAGE privileges.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:NExploitability: 2.8 | Impact: 4.2

Affected Packages3 packages

NVDapache/geode< 1.3.0
Mavenorg.apache.geode:geode-core1.0.01.3.0
CVEListV5apache_software_foundation/apache_geode1.0.0 to 1.2.1

🔴Vulnerability Details

3
OSV
Apache Geode gfsh authorization vulnerability2022-05-14
GHSA
Apache Geode gfsh authorization vulnerability2022-05-14
CVEList
CVE-2017-12622: When an Apache Geode cluster before v12018-01-10
CVE-2017-12622 (HIGH CVSS 7.1) | When an Apache Geode cluster before | cvebase.io