Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Geode
Total 21 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-10091 1 Apache 1 Geode 2020-08-24 4.0 MEDIUM 7.4 HIGH
When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a man-in-the-middle attack.