Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-10091

When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a man-in-the-middle attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 27.7%
CVSS Severity
CVSS v3 Score 7.4
CVSS v2 Score 4.0
Products affected by CVE-2019-10091
  • Apache » Geode » Version: 1.9.0
    cpe:2.3:a:apache:geode:1.9.0


Contact Us

Shodan ® - All rights reserved