An issue was discovered in Pivotal GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x versions prior to 1.7.1. The gfsh (Geode Shell) endpoint, used by operators and application developers to connect to their cluster, is unauthenticated and publicly accessible. Because HTTPS communications are terminated at the gorouter, communications from the gorouter to GemFire clusters are unencrypted. An attacker could run any command available on gfsh and could cause denial of service, lost confidentiality of data, escalate privileges, or eavesdrop on other communications between the gorouter and the cluster.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: dell
Published: 2017-01-06T22:00:00
Updated: 2024-08-06T03:07:30.811Z
Reserved: 2016-12-06T00:00:00
Link: CVE-2016-9885
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-01-06T22:59:00.390
Modified: 2024-11-21T03:01:56.890
Link: CVE-2016-9885
Redhat
No data.