Apache geode
This hub aggregates every CVE we track for Apache geode, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
17
CVEs tracked
2
Critical
9
High
0
In CISA KEV
Severity distribution
HIGH9MEDIUM6CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
2
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache geode.
- CVE-2025-47410Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system8.8
- CVE-2024-44088Apache Geode: Reflected XSS6.1
- CVE-2022-34870Apache Geode stored Cross-Site Scripting (XSS) via data injection vulnerability in Pulse web application5.4
- CVE-2022-37023Apache Geode deserialization of untrusted data flaw when using REST API on Java 8 or Java 116.5
- CVE-2022-37022Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 118.8
- CVE-2022-37021Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 8.9.8
- CVE-2021-34797Apache Geode project log file redaction of sensitive information vulnerability7.5
- CVE-2017-15695When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode function. This a...8.8
- CVE-2017-15692In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they may be able to cau...9.8
- CVE-2017-15693In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objects to be deserialized. A user with DAT...7.5
- CVE-2017-15696When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gain...7.5
- CVE-2017-9795When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries that allow read and write access t...7.5
- CVE-2017-9796When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind...5.3
- CVE-2017-12622When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status informa...7.1
- CVE-2017-9797When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations coul...6.5
Product normalization is registry-driven with AI assist and human review. How it works