oss-sec mailing list archives
[CVE-2019-10091] Apache Geode SSL endpoint verification vulnerability
From: Anthony Baker <abaker () apache org>
Date: Fri, 13 Mar 2020 17:28:26 -0700
CVE-2019-10091 Apache Geode SSL endpoint verification vulnerability Severity: Medium Vendor: The Apache Software Foundation Versions Affected: Apache Geode 1.9.0 Description: When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a man-in-the-middle attack. Mitigation: Users of the affected versions should upgrade to Apache Geode 1.9.1, 1.10.0, or later. Credit: This issue was reported responsibly to the Apache Geode Security Team by Sai Boorlagadda from Pivotal. References: [1] https://issues.apache.org/jira/browse/GEODE-7018 [2] https://cwiki.apache.org/confluence/display/GEODE/Release+Notes#ReleaseNotes-SecurityVulnerabilities
Current thread:
- [CVE-2019-10091] Apache Geode SSL endpoint verification vulnerability Anthony Baker (Mar 14)