Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2022-37023

Apache Geode: REST API deserializes untrusted data

Technology

GemFire / Geode

CVSS Score

6.5 / 10.0

Affected Versions

Apache Geode before 1.15.0

Upstream Fix

1.15.0, with validate-serializable-objects=true

Published

August 31, 2022

OSSeva Coverage

Fixed upstream

Description

The REST API deserializes untrusted data on Java 8 and Java 11. The advisory's fix is to move to Geode 1.15, enable validate-serializable-objects=true and list any application classes in serializable-object-filter; enabling the check may affect performance.

Upstream record: NVD · CVE.org

Is your GemFire / Geode deployment affected?

If you're running Apache Geode before 1.15.0, you need this patch. Book a discovery call to get covered.