CVE-2017-9794
published 2017-09-30CVE-2017-9794: When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In…
PriorityP421medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
1.18%
64.0th percentile
When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In Apache Geode before 1.2.1, the query results may contain data from another user's concurrently executing gfsh query, potentially revealing data that the user is not authorized to view.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | geode | <= 1.2.0 | — |
| apache_software_foundation | apache_geode | — | — |
| apache_software_foundation | apache_geode | — | — |
| apache_software_foundation | apache_geode | — | — |
| apache_software_foundation | apache_geode | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Geode gfsh query vulnerability
osv·2022-05-17
CVE-2017-9794 [MEDIUM] Apache Geode gfsh query vulnerability
Apache Geode gfsh query vulnerability
When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In Apache Geode before 1.2.1, the query results may contain data from another user's concurrently executing gfsh query, potentially revealing data that the user is not authorized to view.
GHSA
Apache Geode gfsh query vulnerability
ghsa·2022-05-17
CVE-2017-9794 [MEDIUM] CWE-200 Apache Geode gfsh query vulnerability
Apache Geode gfsh query vulnerability
When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In Apache Geode before 1.2.1, the query results may contain data from another user's concurrently executing gfsh query, potentially revealing data that the user is not authorized to view.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-09-30
Published