QID 730606

Date Published: 2022-09-20

QID 730606: Apache Geode deserialization of untrusted data flaw when using REST API on Java 8 or Java 11 Vulnerability

Apache Geode is a data management platform that provides real-time, consistent access to data-intensive applications throughout widely distributed cloud architectures.

Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user wishing to protect against deserialization attacks involving REST APIs should upgrade to Apache Geode 1.15 and follow the documentation for details on enabling "validate-serializable-objects=true" and specifying any user classes that may be serialized/deserialized with "serializable-object-filter". Enabling "validate-serializable-objects" may impact performance.
Affected Version
Apache Geode versions prior to 1.15.0 QID Detection Logic:
This QID will check for the affected Apache Geode server version

TBA

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Any user wishing to protect against deserialization attacks involving REST APIs should upgrade to Apache Geode 1.15 and follow the documentation for details on enabling "validate-serializable-objects=true" and specifying any user classes that may be serialized/deserialized with "serializable-object-filter". Enabling "validate-serializable-objects" may impact performance.

    CVEs related to QID 730606

    Software Advisories
    Advisory ID Software Component Link
    GEODE Linux URL Logo lists.apache.org/thread/mg87rh3h773h8sjpm7dhqyldwwtswq7r
    GEODE WIndows URL Logo lists.apache.org/thread/mg87rh3h773h8sjpm7dhqyldwwtswq7r