GHSA-gjp8-99fv-cgcw
HIGHCVE-2025-47410Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target system on behalf of the authenticated user.
- Affected
- >= 1.10.0, < 1.15.2
- Fixed in
- 1.15.2
- Weakness
- CWE-352
- Published
- 2025-10-18
- Source
- github