Skip to main content

Vendor/product archive

apache / geode CVEs

Beta · best-effort

23 CVEs tagged to apache / geode5 Critical, 11 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2025-47410

Published Oct 18, 2025

Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-44088

Published Oct 14, 2025

Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a logged-in user into clicking…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34870

Published Oct 25, 2022

Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse web application to view Region entries.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37023

Published Aug 31, 2022

Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user wishing to protect against dese…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37022

Published Aug 31, 2022

Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user wishing to protect against de…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-37021

Published Aug 31, 2022

Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-34797

Published Jan 4, 2022

Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10091

Published Mar 16, 2020

When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14892

Published Mar 2, 2020

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-co…

CVSS 9.8 · Critical

CVE-2014-0048

Published Jan 2, 2020

An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15752

Published Aug 28, 2019

Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\v…

CVSS 7.8 · High
Buzz score
25.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2017-15694

Published Jun 21, 2019

When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cluster metadata. A ma…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15695

Published Jun 13, 2018

When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geod…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15693

Published Feb 27, 2018

In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objects to be deserialize…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15692

Published Feb 27, 2018

In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-15696

Published Feb 26, 2018

When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9796

Published Jan 10, 2018

When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a reg…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9795

Published Jan 10, 2018

When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries that allow read…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12622

Published Jan 10, 2018

When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obt…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9797

Published Oct 3, 2017

When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metada…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9794

Published Sep 30, 2017

When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries. In Apache Geode before…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5649

Published Apr 4, 2017

Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ but not DATA:READ perm…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1