Re: JGroups vulnerabilty

2020-04-07 Thread Anthony Baker
Thanks for asking Mario. Note that if you want to discuss a security topic prior to public disclosure you can use priv...@geode.apache.org . Anthony > On Apr 7, 2020, at 12:04 PM, Mario Kevo wrote: > > Hi, > > > I was trying to understand whether Geode is

Re: JGroups vulnerabilty

2020-04-07 Thread Bruce Schuchardt
Thanks Mario - Geode uses neither the AUTH nor the ENCRYPT JGroups protocols, so this doesn't apply. On 4/7/20, 12:04 PM, "Mario Kevo" wrote: Hi, I was trying to understand whether Geode is impacted by a security vulnerability reported on JGroups (CVE-2016-2141