Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Fixed in Geronimo 3.0.0
Anchor
221
221

CVE-2013-1777 - "

...

Apache Geronimo 3 RMI classloader exposure" has been fixed via GERONIMO-6253.

Please visit the 3.0.0 Release Notes page for details on all of the ncluded included JIRAs.

Geronimo Server:

CVE-2013-1777: RMI classloader exposure

A misconfigured RMI classloader in Apache Geronimo 3.0 may enable an attacker to send a serialized object via JMX that could compromise the system.

Geronimo 3.0, Beta 1 or M1 users are strongly encouraged to upgrade to Geronimo 3.0

...

.1.

Remote exploits can be prevented by hiding the naming (1099) and JMX (9999) ports behind a firewall or binding the ports to a local network interface.

Affects: 3.0.0, 3.0 Beta 1, and 3.0 M1
JIRA: GERONIMO-6253