Apache Geode SSL endpoint verification vulnerability
High severity
GitHub Reviewed
Published
Feb 10, 2022
to the GitHub Advisory Database
•
Updated Sep 27, 2023
Description
Published by the National Vulnerability Database
Mar 16, 2020
Reviewed
May 3, 2021
Published to the GitHub Advisory Database
Feb 10, 2022
Last updated
Sep 27, 2023
When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a man-in-the-middle attack.
References