When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a man-in-the-middle attack.
2020-03-16T14:15:12.057
2024-11-21T04:18:23.120
Modified
CVSSv3.1: 7.4 (HIGH)
AV:N/AC:H/Au:N/C:P/I:P/A:N
4.9
4.9