
CVE-2017-15695
https://notcve.org/view.php?id=CVE-2017-15695
13 Jun 2018 — When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode function. This allows remote code execution. Code deployment should be restricted to users with DATA:MANAGE privilege. Cuando un servidor de Apache Geode entre las versiones 1.0.0 y 1.4.0 está configurado con un gestor de seguridad, un usuario con privilegios DATA:WRITE puede implementar código mediante la invocación de una funci... • http://www.securityfocus.com/bid/104465 • CWE-863: Incorrect Authorization •

CVE-2017-15693
https://notcve.org/view.php?id=CVE-2017-15693
27 Feb 2018 — In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objects to be deserialized. A user with DATA:WRITE access to the cluster may be able to cause remote code execution if certain classes are present on the classpath. En Apache Geode, en versiones anteriores a la v1.4.0, el servidor Geode almacena objetos de aplicación de forma serializada. Ciertas operaciones del clúster e invocaciones de la API hacen que e... • http://www.securityfocus.com/bid/103206 • CWE-502: Deserialization of Untrusted Data •

CVE-2017-15692
https://notcve.org/view.php?id=CVE-2017-15692
27 Feb 2018 — In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they may be able to cause remote code execution if certain classes are present on the classpath. En Apache Geode, en versiones anteriores a la v1.4.0, el TcpServer en el localizador Geode abre un puerto de red que deserializa datos. Si un usuario sin privilegios obtiene acceso al localizador Geode, podría ser capaz de provocar la ejecuc... • http://www.securityfocus.com/bid/103205 • CWE-502: Deserialization of Untrusted Data •

CVE-2017-15696
https://notcve.org/view.php?id=CVE-2017-15696
26 Feb 2018 — When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains access to the Geode locator to extract configuration data and previously deployed application code. Cuando un clúster de Apache Geode, en versiones anteriores a la v1.4.0, está operando en modo seguro, el servicio de configuración Geode no autoriza las peticiones de configuración correctamente. Esto permite que ... • https://lists.apache.org/thread.html/28989e6ed0d3c29e46a489ae508302a50407a40691d5dc968f78cd3f%40%3Cdev.geode.apache.org%3E • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-9796
https://notcve.org/view.php?id=CVE-2017-9796
10 Jan 2018 — When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind parameter that allow read access to objects within unauthorized regions. Cuando un clúster de Apache Geode en versiones anteriores a la v1.3.0 está operando en modo seguro, un usuario con acceso de lectura a regiones específicas de un clúster Geode podría ejecutar consultas OQL que contienen un nombre de región c... • https://lists.apache.org/thread.html/e580d22195b6b61ff9cf866ac6dd6fe16e790ff0e14a3b1a22cd20b1%40%3Cuser.geode.apache.org%3E • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-9795
https://notcve.org/view.php?id=CVE-2017-9795
10 Jan 2018 — When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries that allow read and write access to objects within unauthorized regions. In addition a user could invoke methods that allow remote code execution. Cuando un clúster de Apache Geode en versiones anteriores a la v1.3.0 está operando en modo seguro, un usuario con acceso de lectura a regiones específicas de un clúster Geode podría ejecutar consultas ... • http://www.securityfocus.com/bid/102488 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-12622
https://notcve.org/view.php?id=CVE-2017-12622
10 Jan 2018 — When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status information and control cluster members even without CLUSTER:MANAGE privileges. Cuando un clúster de Apache Geode en versiones anteriores a la v1.3.0 está operando en modo seguro y un usuario autenticado se conecta a un cúster Geode mediante la herramienta gfsh con HTTP, el usuario puede conseguir información de estado y... • https://lists.apache.org/thread.html/560578479dabbdc93d0ee8746b7c857549202ef82f43aa22496aa589%40%3Cuser.geode.apache.org%3E • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-9797
https://notcve.org/view.php?id=CVE-2017-9797
02 Oct 2017 — When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could leak information about application data types. In addition, an attacker could perform a denial of service attack on the cluster. Cuando un clúster de Apache Geode en versiones anteriores a la 1.2.1 opera en modo seguro, un cliente sin autenticar puede entrar en modo de autenticación multi-user y enviar mensajes ... • http://mail-archives.apache.org/mod_mbox/geode-user/201709.mbox/%3cCAEwge-Hrbb7JS8Nygrh7geyFvW4bMZ3AdCmPOzMfvbniipz0bA%40mail.gmail.com%3e • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-9794
https://notcve.org/view.php?id=CVE-2017-9794
29 Sep 2017 — When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In Apache Geode before 1.2.1, the query results may contain data from another user's concurrently executing gfsh query, potentially revealing data that the user is not authorized to view. Cuando se opera un clúster en modo seguro, un usuario con privilegios de lectura para determinadas regiones de datos podría utilizar la herramienta de línea de comandos... • http://mail-archives.apache.org/mod_mbox/geode-user/201709.mbox/%3cCAEwge-FqzrT+deCkNkM-EQZuKfg-XuqY4cGjFiqxoKBVduY1Zw%40mail.gmail.com%3e • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-5649
https://notcve.org/view.php?id=CVE-2017-5649
04 Apr 2017 — Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ but not DATA:READ permission to access the data browser page in Pulse and consequently execute an OQL query that exposes data stored in the cluster. Apache Geode en versiones anteriores a 1.1.1, cuando un clúster ha habilitado seguridad al establecer la propiedad security-manager, permite a los usuarios autenticados remotos con CLUSTER:READ pero no con ... • http://mail-archives.apache.org/mod_mbox/geode-user/201704.mbox/%3cCAEwge-E4y=EVfhwpfRwsbnBH_hBS3Q-BJS+1BX5omYGW4dnR1w%40mail.gmail.com%3e • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •