Apache Geode
Apache · 18 CVEs
Apache Geode: Management REST API: Insertion of Sensitive Information into Log File
Oct 7, 2026
Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh command…
Oct 18, 2025
Apache Geode: Reflected XSS
Oct 14, 2025
Apache Geode stored Cross-Site Scripting (XSS) via data injection vulnerability in Pulse web application
Oct 25, 2022
Apache Geode deserialization of untrusted data flaw when using REST API on Java 8 or Java 11
Aug 31, 2022
Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 11
Aug 31, 2022
Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 8.
Aug 31, 2022
Apache Geode project log file redaction of sensitive information vulnerability
Jan 4, 2022
When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privi…
Jun 13, 2018
In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operatio…
Feb 27, 2018
In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If a…
Feb 27, 2018
When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not proper…
Feb 26, 2018
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions wit…
Jan 10, 2018
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions wit…
Jan 10, 2018
When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cl…
Jan 10, 2018
When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user…
Oct 2, 2017
When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh comm…
Sep 29, 2017
Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote…
Apr 4, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-103371 | Apache Geode: Management REST API: Insertion of Sensitive Information into Log File | n/a | n/a | Oct 7, 2026 |
| CVE-2025-47410 | Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system | HIGH | 0.36% | Oct 18, 2025 |
| CVE-2024-44088 | Apache Geode: Reflected XSS | MEDIUM | 0.69% | Oct 14, 2025 |
| CVE-2022-34870 | Apache Geode stored Cross-Site Scripting (XSS) via data injection vulnerability in Pulse web application | MEDIUM | 1.24% | Oct 25, 2022 |
| CVE-2022-37023 | Apache Geode deserialization of untrusted data flaw when using REST API on Java 8 or Java 11 | MEDIUM | 1.67% | Aug 31, 2022 |
| CVE-2022-37022 | Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 11 | HIGH | 1.48% | Aug 31, 2022 |
| CVE-2022-37021 | Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 8. | CRITICAL | 2.58% | Aug 31, 2022 |
| CVE-2021-34797 | Apache Geode project log file redaction of sensitive information vulnerability | HIGH | 2.51% | Jan 4, 2022 |
| CVE-2017-15695 | When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invok… | HIGH | 2.61% | Jun 13, 2018 |
| CVE-2017-15693 | In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objec… | HIGH | 2.47% | Feb 27, 2018 |
| CVE-2017-15692 | In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the… | CRITICAL | 4.78% | Feb 27, 2018 |
| CVE-2017-15696 | When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. Thi… | HIGH | 2.00% | Feb 26, 2018 |
| CVE-2017-9796 | When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL quer… | MEDIUM | 1.48% | Jan 10, 2018 |
| CVE-2017-9795 | When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL quer… | HIGH | 4.18% | Jan 10, 2018 |
| CVE-2017-12622 | When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the… | HIGH | 2.08% | Jan 10, 2018 |
| CVE-2017-9797 | When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata me… | MEDIUM | 1.36% | Oct 2, 2017 |
| CVE-2017-9794 | When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In… | MEDIUM | 1.18% | Sep 29, 2017 |
| CVE-2017-5649 | Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ bu… | HIGH | 2.78% | Apr 4, 2017 |
Showing 1 to 18 of 18 CVEs