{"id":"CVE-2017-5649","aliases":["GHSA-2gw6-73wc-x88f"],"url":"https://o3.security/vulnerability/CVE-2017-5649","summary":"Apache Geode information disclosure vulnerability","details":"Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ but not DATA:READ permission to access the data browser page in Pulse and consequently execute an OQL query that exposes data stored in the cluster.","published":"2017-04-04T18:59:00.233Z","modified":"2026-07-08T12:05:20.431417Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.geode:geode-core","fixedVersion":"1.1.1"}],"fix":null,"references":[{"type":"WEB","url":"http://mail-archives.apache.org/mod_mbox/geode-user/201704.mbox/%3cCAEwge-E4y=EVfhwpfRwsbnBH_hBS3Q-BJS+1BX5omYGW4dnR1w%40mail.gmail.com%3e"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/97378"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:05:20.431417Z"}}