Apache / Geode
23 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-47410 | Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system | HIGH | 8.8 | Oct 18, 2025 |
| CVE-2024-44088 | Apache Geode: Reflected XSS | MEDIUM | 6.1 | Oct 14, 2025 |
| CVE-2022-34870 | Apache Geode stored Cross-Site Scripting (XSS) via data injection vulnerability in Pulse web application | MEDIUM | 5.4 | Oct 25, 2022 |
| CVE-2022-37023 | Apache Geode deserialization of untrusted data flaw when using REST API on Java 8 or Java 11 | MEDIUM | 6.5 | Aug 31, 2022 |
| CVE-2022-37022 | Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 11 | HIGH | 8.8 | Aug 31, 2022 |
| CVE-2022-37021 | Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 8. | CRITICAL | 9.8 | Aug 31, 2022 |
| CVE-2021-34797 | Apache Geode project log file redaction of sensitive information vulnerability | HIGH | 7.5 | Jan 4, 2022 |
| CVE-2019-10091 | When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate… | HIGH | 7.4 | Mar 16, 2020 |
| CVE-2019-14892 | jackson-databind: Serialization gadgets in classes of the commons-configuration package | CRITICAL | 9.8 | Mar 2, 2020 |
| CVE-2020-1938 KEV | tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability | CRITICAL | 9.8 | Feb 24, 2020 |
| CVE-2014-0048 | Docker: multiple files downloaded over HTTP and executed or used unsafely | CRITICAL | 9.8 | Jan 2, 2020 |
| CVE-2019-15752 KEV | Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMD… | HIGH | 7.8 | Aug 28, 2019 |
| CVE-2017-15694 | When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cl… | MEDIUM | 6.5 | Jun 21, 2019 |
| CVE-2017-15695 | When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invok… | HIGH | 8.8 | Jun 13, 2018 |
| CVE-2017-15693 | In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objec… | HIGH | 7.5 | Feb 27, 2018 |
| CVE-2017-15692 | In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the… | CRITICAL | 9.8 | Feb 27, 2018 |
| CVE-2017-15696 | When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. Thi… | HIGH | 7.5 | Feb 26, 2018 |
| CVE-2017-9796 | When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL quer… | MEDIUM | 5.3 | Jan 10, 2018 |
| CVE-2017-9795 | When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL quer… | HIGH | 7.5 | Jan 10, 2018 |
| CVE-2017-12622 | When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the… | HIGH | 7.1 | Jan 10, 2018 |
| CVE-2017-9797 | When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata me… | MEDIUM | 6.5 | Oct 2, 2017 |
| CVE-2017-9794 | When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In… | MEDIUM | 4.3 | Sep 29, 2017 |
| CVE-2017-5649 | Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ bu… | HIGH | 7.5 | Apr 4, 2017 |
Showing 1 to 23 of 23 CVEs