Back

MEDIUM

When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries

Published Sep 29, 2017

Description

When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In Apache Geode before 1.2.1, the query results may contain data from another user's concurrently executing gfsh query, potentially revealing data that the user is not authorized to view.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 29, 2017
Updated Sep 17, 2024
Reserved Jun 21, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-37M3-QP37-X3C6