PT-2025-41925 · Apache · Apache Geode
Nbxiglk
·
Published
2025-10-14
·
Updated
2025-10-17
·
CVE-2024-44088
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Geode versions prior to 1.15.2
Description
A malicious script injection issue exists in the Apache Geode web-api (REST). An attacker can trick a logged-in user into clicking a specially-crafted link, leading to code execution on the returned page. This could result in the theft of the user's session information and potential account takeover. The vulnerability impacts the REST API.
Recommendations
Upgrade to version 1.15.2, which resolves the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Geode