VulnerabilityModified
CVE-2017-15696
This allows an unprivileged user who gains access to the Geode locator to extract configuration data and previously deployed application code.
HIGH 7.5EPSS 2.00%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.00%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains access to the Geode locator to extract configuration data and previously deployed application code.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.00% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apache/geode
- Source
- security@apache.org
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.