Apache Geode

Apache · 18 CVEs

CVE-2026-103371

Apache Geode: Management REST API: Insertion of Sensitive Information into Log File

Oct 7, 2026

CVE-2025-47410
HIGH

Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh command…

Oct 18, 2025

CVE-2024-44088
MEDIUM

Apache Geode: Reflected XSS

Oct 14, 2025

CVE-2022-34870
MEDIUM

Apache Geode stored Cross-Site Scripting (XSS) via data injection vulnerability in Pulse web application

Oct 25, 2022

CVE-2022-37023
MEDIUM

Apache Geode deserialization of untrusted data flaw when using REST API on Java 8 or Java 11

Aug 31, 2022

CVE-2022-37022
HIGH

Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 11

Aug 31, 2022

CVE-2022-37021
CRITICAL

Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 8.

Aug 31, 2022

CVE-2021-34797
HIGH

Apache Geode project log file redaction of sensitive information vulnerability

Jan 4, 2022

CVE-2017-15695
HIGH

When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privi…

Jun 13, 2018

CVE-2017-15693
HIGH

In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operatio…

Feb 27, 2018

CVE-2017-15692
CRITICAL

In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If a…

Feb 27, 2018

CVE-2017-15696
HIGH

When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not proper…

Feb 26, 2018

CVE-2017-9796
MEDIUM

When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions wit…

Jan 10, 2018

CVE-2017-9795
HIGH

When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions wit…

Jan 10, 2018

CVE-2017-12622
HIGH

When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cl…

Jan 10, 2018

CVE-2017-9797
MEDIUM

When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user…

Oct 2, 2017

CVE-2017-9794
MEDIUM

When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh comm…

Sep 29, 2017

CVE-2017-5649
HIGH

Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote…

Apr 4, 2017

Showing 1 to 18 of 18 CVEs