PT-2025-42650 · Apache · Apache Geode
Published
2025-10-17
·
Updated
2025-10-28
·
CVE-2025-47410
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Geode versions 1.10 through 1.15.1
Description
Apache Geode is susceptible to Cross-Site Request Forgery (CSRF) attacks via GET requests to the Management and Monitoring REST API. Successful exploitation could allow an attacker to execute malicious commands on a target system, acting on behalf of an authenticated user who has been tricked into revealing their Geode session credentials. The vulnerable API allows the execution of
gfsh commands.Recommendations
Upgrade to version 1.15.2 to resolve the issue.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Geode