Back to Vulnerability Directory
HIGHFixed upstream

CVE-2022-37022

Apache Geode: JMX over RMI on Java 11 deserializes untrusted data

Technology

GemFire / Geode

CVSS Score

8.8 / 10.0

Affected Versions

Apache Geode 1.12.2 and earlier and 1.13.0 to 1.13.2, using JMX over RMI on Java 11

Upstream Fix

1.15.0

Published

August 31, 2022

OSSeva Coverage

Fixed upstream

Description

Geode deserializes untrusted data when JMX over RMI is used on Java 11. The advisory's fix is Geode 1.15, which protects JMX over RMI against deserialization attacks automatically on Java 11.

Upstream record: NVD · CVE.org

Is your GemFire / Geode deployment affected?

If you're running Apache Geode 1.12.2 and earlier and 1.13.0 to 1.13.2, using JMX over RMI on Java 11, you need this patch. Book a discovery call to get covered.