{"id":"CVE-2017-15695","details":"When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode function. This allows remote code execution. Code deployment should be restricted to users with DATA:MANAGE privilege.","aliases":["GHSA-jmg4-x4vp-6c6x"],"modified":"2026-04-10T03:57:34.972957Z","published":"2018-06-13T17:29:00.220Z","references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/dc8875c0b924885a884eba6d5bd7dc3f123411b2d33cffd00e351c99%40%3Cuser.geode.apache.org%3E"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/104465"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/geode","events":[{"introduced":"280a407c59a89401d5d87d6e6aeda1c975870753"},{"last_affected":"2a70679608120042fa7cbee67f4dd21a085d9588"}],"database_specific":{"versions":[{"introduced":"1.0.0"},{"last_affected":"1.4.0"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-15695.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}