Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user wishing to protect against deserialization attacks involving REST APIs should upgrade to Apache Geode 1.15 and follow the documentation for details on enabling validate-serializable-objects=true and specifying any user classes that may be serialized/deserialized with serializable-object-filter. Enabling validate-serializable-objects may impact performance.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Geode | Apache | * | 1.15.0 (excluding) |