CVE-2017-9797
published 2017-10-03CVE-2017-9797: When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata…
PriorityP431medium6.5CVSS 3.0
AVNACHPRNUINSUCLINAH
EPSS
1.36%
68.5th percentile
When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could leak information about application data types. In addition, an attacker could perform a denial of service attack on the cluster.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | geode | <= 1.2.0 | — |
| apache_software_foundation | apache_geode | — | — |
| apache_software_foundation | apache_geode | — | — |
| apache_software_foundation | apache_geode | — | — |
| apache_software_foundation | apache_geode | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Geode vulnerable to Exposure of Sensitive Information
ghsa·2022-05-13
CVE-2017-9797 [MEDIUM] CWE-200 Apache Geode vulnerable to Exposure of Sensitive Information
Apache Geode vulnerable to Exposure of Sensitive Information
When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could leak information about application data types. In addition, an attacker could perform a denial of service attack on the cluster.
OSV
Apache Geode vulnerable to Exposure of Sensitive Information
osv·2022-05-13
CVE-2017-9797 [MEDIUM] Apache Geode vulnerable to Exposure of Sensitive Information
Apache Geode vulnerable to Exposure of Sensitive Information
When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could leak information about application data types. In addition, an attacker could perform a denial of service attack on the cluster.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-03
Published