Логотип exploitDog
bind:CVE-2025-47410
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-47410

Количество 2

Количество 2

nvd логотип

CVE-2025-47410

4 месяца назад

Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target system on behalf of the authenticated user. This issue affects Apache Geode: versions 1.10 through 1.15.1 Users are recommended to upgrade to version 1.15.2, which fixes the issue.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-gjp8-99fv-cgcw

4 месяца назад

Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-47410

Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target system on behalf of the authenticated user. This issue affects Apache Geode: versions 1.10 through 1.15.1 Users are recommended to upgrade to version 1.15.2, which fixes the issue.

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-gjp8-99fv-cgcw

Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system

CVSS3: 8.8
0%
Низкий
4 месяца назад

Уязвимостей на страницу