Description
When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status information and control cluster members even without CLUSTER:MANAGE privileges.
Remediation
References
https://lists.apache.org/thread.html/560578479dabbdc93d0ee8746b7c857549202ef82f43aa22496aa589%40%3Cuser.geode.apache.org%3E
Related Vulnerabilities
CVE-2017-2609 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-1000402 Vulnerability in maven package org.jenkins-ci.plugins:codedeploy
CVE-2019-10247 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2011-4343 Vulnerability in maven package org.apache.myfaces.core:myfaces-impl
CVE-2018-1192 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-uaa