When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status information and control cluster members even without CLUSTER:MANAGE privileges.
2018-01-10T03:29:00.187
2024-11-21T03:09:54.980
Modified
CVSSv3.0: 7.1 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9