Known Vulnerabilities for Geode by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Geode" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-37023 json | Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java ... | 6.5 - MEDIUM | 2022-08-31 | 2022-09-06 |
| CVE-2022-37022 json | Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over ... | 8.8 - HIGH | 2022-08-31 | 2022-09-06 |
| CVE-2022-37021 json | Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using J... | 9.8 - CRITICAL | 2022-08-31 | 2022-09-07 |
| CVE-2022-34870 json | Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse web app... | 5.4 - MEDIUM | 2022-10-25 | 2022-10-26 |
| CVE-2021-34797 json | Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using... | 7.5 - HIGH | 2022-01-04 | 2022-01-12 |
| CVE-2020-1938 json | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat tr... | 9.8 - CRITICAL | 2020-02-24 | 2023-11-07 |
| CVE-2019-14892 json | A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic ... | 9.8 - CRITICAL | 2020-03-02 | 2023-11-07 |
| CVE-2019-10091 json | When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification... | 7.4 - HIGH | 2020-03-16 | 2020-08-24 |
| CVE-2017-15696 json | When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly aut... | 7.5 - HIGH | 2018-02-26 | 2023-11-07 |
| CVE-2017-15695 json | When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges ... | 8.8 - HIGH | 2018-06-13 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Geode | 1.9.2 | |||
| Application | Apache | Geode | 1.9.1 | |||
| Application | Apache | Geode | 1.9.0 | |||
| Application | Apache | Geode | 1.8.0 | |||
| Application | Apache | Geode | 1.7.0 | |||
| Application | Apache | Geode | 1.6.0 | |||
| Application | Apache | Geode | 1.5.0 | |||
| Application | Apache | Geode | 1.4.0 | |||
| Application | Apache | Geode | 1.3.0 | |||
| Application | Apache | Geode | 1.2.1 | |||
| Application | Apache | Geode | 1.2.0 | |||
| Application | Apache | Geode | 1.11.0 | |||
| Application | Apache | Geode | 1.10.0 | |||
| Application | Apache | Geode | 1.1.1 | |||
| Application | Apache | Geode | 1.1.0 | |||
| Application | Apache | Geode | 1.0.0 |