Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target system on behalf of the authenticated user.


This issue affects Apache Geode: versions 1.10 through 1.15.1

Users are recommended to upgrade to version 1.15.2, which fixes the issue.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gjp8-99fv-cgcw Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Nov 2025 07:30:00 +0900

Type Values Removed Values Added
References

Tue, 28 Oct 2025 23:45:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:geode:*:*:*:*:*:*:*:*

Mon, 20 Oct 2025 23:15:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Oct 2025 22:30:00 +0900

Type Values Removed Values Added
First Time appeared Apache
Apache geode
Vendors & Products Apache
Apache geode

Sun, 19 Oct 2025 00:30:00 +0900

Type Values Removed Values Added
Description Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target system on behalf of the authenticated user. This issue affects Apache Geode: versions 1.10 through 1.15.1 Users are recommended to upgrade to version 1.15.2, which fixes the issue.
Title Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system
Weaknesses CWE-352
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-11-04T21:10:53.480Z

Reserved: 2025-05-06T13:16:19.188Z

Link: CVE-2025-47410

cve-icon Vulnrichment

Updated: 2025-11-04T21:10:53.480Z

cve-icon NVD

Status : Modified

Published: 2025-10-18T16:15:35.557

Modified: 2025-11-04T22:16:16.040

Link: CVE-2025-47410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-20T22:21:29Z

Weaknesses