{"id":"GHSA-vh98-fqfc-4hj3","summary":"Apache Geode vulnerable to Exposure of Sensitive Information","details":"When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could leak information about application data types. In addition, an attacker could perform a denial of service attack on the cluster.","aliases":["CVE-2017-9797"],"modified":"2023-11-08T03:59:29.564543Z","published":"2022-05-13T01:48:08Z","database_specific":{"cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-11-08T14:24:20Z","nvd_published_at":"2017-10-03T01:29:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-9797"},{"type":"WEB","url":"https://cwiki.apache.org/confluence/display/GEODE/Release+Notes#ReleaseNotes-SecurityVulnerabilities"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/GEODE-3249"},{"type":"WEB","url":"http://mail-archives.apache.org/mod_mbox/geode-user/201709.mbox/%3cCAEwge-Hrbb7JS8Nygrh7geyFvW4bMZ3AdCmPOzMfvbniipz0bA@mail.gmail.com%3e"}],"affected":[{"package":{"name":"org.apache.geode:geode-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.geode/geode-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.2.1"}]}],"versions":["1.0.0-incubating","1.0.0-incubating.M2","1.0.0-incubating.M3","1.1.0","1.1.1","1.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-vh98-fqfc-4hj3/GHSA-vh98-fqfc-4hj3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H"}]}