Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2022-37021

Apache Geode: JMX over RMI on Java 8 deserializes untrusted data

Technology

GemFire / Geode

CVSS Score

9.8 / 10.0

Affected Versions

Apache Geode 1.12.5 and earlier, 1.13.0 to 1.13.4, and 1.14.0, using JMX over RMI on Java 8

Upstream Fix

1.15.0 on Java 11, or 1.15.0 on Java 8 with -Dgeode.enableGlobalSerialFilter=true

Published

August 31, 2022

OSSeva Coverage

Fixed upstream

Description

Geode deserializes untrusted data when JMX over RMI is used on Java 8. Gfsh uses JMX over RMI to talk to the JMX Manager hosted on a locator. The advisory's fix is to move to Geode 1.15 and Java 11; where Java 11 is not possible, start every locator and server on 1.15 with -Dgeode.enableGlobalSerialFilter=true and list application classes in serializable-object-filter, which affects performance.

Upstream record: NVD · CVE.org

Is your GemFire / Geode deployment affected?

If you're running Apache Geode 1.12.5 and earlier, 1.13.0 to 1.13.4, and 1.14.0, using JMX over RMI on Java 8, you need this patch. Book a discovery call to get covered.