PT-2022-4605 · Apache · Apache Geode

Kirk Lund

·

Published

2022-08-31

·

Updated

2022-09-06

·

CVE-2022-37023

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Geode versions prior to 1.15.0
Description The issue is related to the restoration of untrusted data in memory through the REST API interface of the Apache Geode data management platform. This can allow a remote attacker to execute arbitrary code. The vulnerability is associated with the deserialization of untrusted data when using the REST API on Java 8 or Java 11.
Recommendations To protect against deserialization attacks involving REST APIs, upgrade to Apache Geode 1.15.0 and follow the documentation for details on enabling validate-serializable-objects=true and specifying any user classes that may be serialized/deserialized with serializable-object-filter. Note that enabling validate-serializable-objects may impact performance.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2022-05483
CVE-2022-37023
GHSA-72X9-48MC-PHH6

Affected Products

Apache Geode