Known Vulnerabilities for Geode by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Geode" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-34797 | Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using... | 7.5 - HIGH | 2022-01-04 | 2022-01-12 |
| CVE-2020-1938 | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat tr... | 9.8 - CRITICAL | 2020-02-24 | 2023-11-07 |
| CVE-2019-14892 | A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic ... | 9.8 - CRITICAL | 2020-03-02 | 2023-11-07 |
| CVE-2019-10091 | When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification... | 7.4 - HIGH | 2020-03-16 | 2020-08-24 |
| CVE-2017-12622 | When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster ... | 7.1 - HIGH | 2018-01-10 | 2023-11-07 |
| CVE-2017-9797 | When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authen... | 6.5 - MEDIUM | 2017-10-03 | 2023-11-07 |
| CVE-2017-9796 | When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a ... | 5.3 - MEDIUM | 2018-01-10 | 2023-11-07 |
| CVE-2017-9795 | When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a ... | 7.5 - HIGH | 2018-01-10 | 2023-11-07 |
| CVE-2017-9794 | When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command li... | 4.3 - MEDIUM | 2017-09-30 | 2023-11-07 |
| CVE-2017-5649 | Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authen... | 7.5 - HIGH | 2017-04-04 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Geode | 1.9.2 | All | All | All |
| Application | Apache | Geode | 1.9.1 | All | All | All |
| Application | Apache | Geode | 1.9.0 | All | All | All |
| Application | Apache | Geode | 1.8.0 | All | All | All |
| Application | Apache | Geode | 1.7.0 | All | All | All |
| Application | Apache | Geode | 1.6.0 | All | All | All |
| Application | Apache | Geode | 1.5.0 | All | All | All |
| Application | Apache | Geode | 1.4.0 | All | All | All |
| Application | Apache | Geode | 1.3.0 | All | All | All |
| Application | Apache | Geode | 1.2.1 | All | All | All |
| Application | Apache | Geode | 1.2.0 | All | All | All |
| Application | Apache | Geode | 1.11.0 | All | All | All |
| Application | Apache | Geode | 1.10.0 | All | All | All |
| Application | Apache | Geode | 1.1.1 | All | All | All |
| Application | Apache | Geode | 1.1.0 | All | All | All |
| Application | Apache | Geode | 1.0.0 | All | All | All |