Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2017-15692

Apache Geode: locator TcpServer deserializes data from the network

Technology

GemFire / Geode

CVSS Score

9.8 / 10.0

Affected Versions

Apache Geode before 1.4.0

Upstream Fix

1.4.0

Published

February 27, 2018

OSSeva Coverage

Fixed upstream

Description

The TcpServer within the Geode locator opens a network port that deserializes data. An unprivileged user who can reach the locator may be able to run code if certain classes are present on the classpath.

Upstream record: NVD · CVE.org

Is your GemFire / Geode deployment affected?

If you're running Apache Geode before 1.4.0, you need this patch. Book a discovery call to get covered.