[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] [CVE-2019-10091] Apache Geode SSL endpoint verification vulnerability
From:       Anthony Baker <abaker () apache ! org>
Date:       2020-03-14 0:28:26
Message-ID: CAEwge-G24JXjkEEayqufi=zon-mo5usfiS3H8MYvtpg8=g0HuA () mail ! gmail ! com
[Download RAW message or body]

CVE-2019-10091 Apache Geode SSL endpoint verification vulnerability

Severity: Medium

Vendor: The Apache Software Foundation

Versions Affected:
Apache Geode 1.9.0

Description:
When TLS is enabled with ssl-endpoint-identification-enabled set to
true, Apache Geode fails to perform hostname verification of the
entries in the certificate SAN during the SSL handshake.  This could
compromise intra-cluster communication using a man-in-the-middle
attack.

Mitigation:
Users of the affected versions should upgrade to Apache Geode 1.9.1,
1.10.0, or later.

Credit:
This issue was reported responsibly to the Apache Geode Security Team
by Sai Boorlagadda from Pivotal.

References:
[1] https://issues.apache.org/jira/browse/GEODE-7018
[2] https://cwiki.apache.org/confluence/display/GEODE/Release+Notes#ReleaseNotes-SecurityVulnerabilities
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic