
====================================================================

                             CERT-Renater

                 Note d'Information No. 2020/VULN163
_____________________________________________________________________

DATE                : 25/03/2020

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache Geode versions prior to
                                    1.9.1, 1.10.0.

=====================================================================
http://mail-archives.apache.org/mod_mbox/www-announce/202003.mbox/%3cCAEwge-G24JXjkEEayqufi=zon-mo5usfiS3H8MYvtpg8=g0HuA@mail.gmail.com%3e
_____________________________________________________________________


CVE-2019-10091 Apache Geode SSL endpoint verification vulnerability


Severity: Medium

Vendor: The Apache Software Foundation

Versions Affected:
Apache Geode 1.9.0


Description:
When TLS is enabled with ssl-endpoint-identification-enabled set to
true, Apache Geode fails to perform hostname verification of the
entries in the certificate SAN during the SSL handshake.  This could
compromise intra-cluster communication using a man-in-the-middle
attack.


Mitigation:
Users of the affected versions should upgrade to Apache Geode 1.9.1,
1.10.0, or later.


Credit:
This issue was reported responsibly to the Apache Geode Security Team
by Sai Boorlagadda from Pivotal.

References:
[1] https://issues.apache.org/jira/browse/GEODE-7018
[2]
https://cwiki.apache.org/confluence/display/GEODE/Release+Notes#ReleaseNotes-SecurityVulnerabilities


=========================================================
+ CERT-RENATER        | tel : 01-53-94-20-44            +
+ 23/25 Rue Daviel    | fax : 01-53-94-20-41            +
+ 75013 Paris         | email:cert@support.renater.fr   +
=========================================================






