Description
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind parameter that allow read access to objects within unauthorized regions.
Remediation
References
https://lists.apache.org/thread.html/e580d22195b6b61ff9cf866ac6dd6fe16e790ff0e14a3b1a22cd20b1%40%3Cuser.geode.apache.org%3E
Related Vulnerabilities
CVE-2013-6447 Vulnerability in maven package org.jboss.seam:jboss-seam-remoting
CVE-2018-1000145 Vulnerability in maven package org.jvnet.hudson.plugins:perforce
CVE-2014-3680 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2019-10246 Vulnerability in maven package org.eclipse.jetty:jetty-util
CVE-2017-1000505 Vulnerability in maven package org.jenkins-ci.plugins:script-security