CVE-2022-37021
Apache Geode: JMX over RMI on Java 8 deserializes untrusted data
Technology
GemFire / Geode
CVSS Score
9.8 / 10.0
Affected Versions
Apache Geode 1.12.5 and earlier, 1.13.0 to 1.13.4, and 1.14.0, using JMX over RMI on Java 8
Upstream Fix
1.15.0 on Java 11, or 1.15.0 on Java 8 with -Dgeode.enableGlobalSerialFilter=true
Published
August 31, 2022
OSSeva Coverage
Fixed upstream
Description
Geode deserializes untrusted data when JMX over RMI is used on Java 8. Gfsh uses JMX over RMI to talk to the JMX Manager hosted on a locator. The advisory's fix is to move to Geode 1.15 and Java 11; where Java 11 is not possible, start every locator and server on 1.15 with -Dgeode.enableGlobalSerialFilter=true and list application classes in serializable-object-filter, which affects performance.
Is your GemFire / Geode deployment affected?
If you're running Apache Geode 1.12.5 and earlier, 1.13.0 to 1.13.4, and 1.14.0, using JMX over RMI on Java 8, you need this patch. Book a discovery call to get covered.