PT-2025-42650 · Apache · Apache Geode

Published

2025-10-17

·

Updated

2025-10-28

·

CVE-2025-47410

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Geode versions 1.10 through 1.15.1
Description Apache Geode is susceptible to Cross-Site Request Forgery (CSRF) attacks via GET requests to the Management and Monitoring REST API. Successful exploitation could allow an attacker to execute malicious commands on a target system, acting on behalf of an authenticated user who has been tricked into revealing their Geode session credentials. The vulnerable API allows the execution of gfsh commands.
Recommendations Upgrade to version 1.15.2 to resolve the issue.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-47410
GHSA-GJP8-99FV-CGCW

Affected Products

Apache Geode