QID 981697
QID 981697: Java (maven) Security Update for org.apache.geode:geode-core (GHSA-p426-qw2p-v95v)
When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cluster metadata. A malicious user could modify this data in a way that affects the operation of the cluster.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-p426-qw2p-v95v for updates pertaining to this vulnerability.
Vendor References
- GHSA-p426-qw2p-v95v -
github.com/advisories/GHSA-p426-qw2p-v95v
CVEs related to QID 981697
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-p426-qw2p-v95v | org.apache.geode:geode-core |
|