CVE-2017-12622
When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status information and control cluster members even without CLUSTER:MANAGE privileges.
- Affected products
- Apache Geode
- Apache Geode
- < 1.3.0
- CVSS 3.0
- 7.1 HIGH
- EPSS
- 2.1% (80th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2018-01-10
CVE-2017-12622 at NVD
3 known exploits for CVE-2017-12622
Proof-of-concept code and exploit modules indexed by Sploitus