CVE-2019-10091
HIGH7.4EPSS 0.13%Apache Geode SSL endpoint verification vulnerability
Published: 2/10/2022Modified: 2/16/2024
Description
When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a man-in-the-middle attack.
Affected packages (1)
- Maven/org.apache.geode:geode-corefrom 0, < 1.10.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.4 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
References (6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2019-10091
- WEBhttps://cwiki.apache.org/confluence/display/GEODE/Release+Notes#ReleaseNotes-SecurityVulnerabilities
- WEBhttps://github.com/apache/geode/commit/e57028fd62a2f5980ea6c9a7ab89ada06c828634
- WEBhttps://github.com/apache/geode/pull/3849
- WEBhttps://issues.apache.org/jira/browse/GEODE-7018
- WEBhttps://lists.apache.org/thread.html/r3342077ac4798631300366be86e545d0c08753cca8fd2663867fe200%40%3Cdev.geode.apache.org%3E