Re: [SECURITY] CVE-2017-9796 Apache Geode OQL bind parameter vulnerability

2018-01-11 Thread Kevin Connolly
Please remove me from all future emails and distributions. Thanks, Kevin Sent from my iPhone > On Jan 9, 2018, at 5:05 PM, Anthony Baker wrote: > > CVE-2017-9796 Apache Geode OQL bind parameter vulnerability > > Severity: Important > > Vendor: The Apache Software Foundation > > Versions

[SECURITY] CVE-2017-9796 Apache Geode OQL bind parameter vulnerability

2018-01-09 Thread Anthony Baker
CVE-2017-9796 Apache Geode OQL bind parameter vulnerability Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Geode 1.0.0 through 1.2.1 Description: A malicious user with read access to specific regions within a Geode cluster may execute OQL queries containi