Apache

Geode

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 18.10.2025 15:15:09
  • Zuletzt bearbeitet 04.11.2025 22:16:16

Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target sy...

  • EPSS 0.13%
  • Veröffentlicht 14.10.2025 14:36:52
  • Zuletzt bearbeitet 04.11.2025 22:16:03

Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a logged-in user into clicking a specially-crafted link to execute code on the returned page, which co...

  • EPSS 2.57%
  • Veröffentlicht 25.10.2022 17:15:53
  • Zuletzt bearbeitet 09.05.2025 19:15:54

Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse web application to view Region entries.

  • EPSS 0.4%
  • Veröffentlicht 31.08.2022 07:15:07
  • Zuletzt bearbeitet 21.11.2024 07:14:18

Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user wishing to protect against deserialization attacks involving REST APIs should upgrade to Apache Geode ...

  • EPSS 0.32%
  • Veröffentlicht 31.08.2022 07:15:07
  • Zuletzt bearbeitet 21.11.2024 07:14:18

Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user wishing to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geo...

  • EPSS 0.76%
  • Veröffentlicht 31.08.2022 07:15:07
  • Zuletzt bearbeitet 21.11.2024 07:14:18

Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JMX or RMI sh...

  • EPSS 0.28%
  • Veröffentlicht 04.01.2022 09:15:07
  • Zuletzt bearbeitet 21.11.2024 06:11:13

Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "syspr...

  • EPSS 0.1%
  • Veröffentlicht 16.03.2020 14:15:12
  • Zuletzt bearbeitet 21.11.2024 04:18:23

When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a ma...

  • EPSS 1.37%
  • Veröffentlicht 02.03.2020 17:15:17
  • Zuletzt bearbeitet 21.11.2024 04:27:37

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to ex...

Warnung Exploit
  • EPSS 94.47%
  • Veröffentlicht 24.02.2020 22:15:12
  • Zuletzt bearbeitet 27.10.2025 17:37:12

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available t...