CVE-2019-10091: Apache Geode
High severity, CVSS 7.4. EPSS: 1.4% chance of exploitation in the next 30 days.
When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a man-in-the-middle attack.
Affected products
- Apache Geode: version 1.9.0 only
Published 2020-03-16. Last modified 2026-06-17.