Org.apache.geode:geode-core
17 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Org.apache.geode:geode-core, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Org.apache.geode:geode-core CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 17 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High9
- Medium6
Latest CVEs
The 15 most recently published vulnerabilities affecting Org.apache.geode:geode-core.
- CVE-2022-34870Apache Geode stored Cross-Site Scripting (XSS) via data injection vulnerability in Pulse web application5.4
- CVE-2022-37023Apache Geode deserialization of untrusted data flaw when using REST API on Java 8 or Java 116.5
- CVE-2022-37022Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 118.8
- CVE-2022-37021Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 8.9.8
- CVE-2021-34797Apache Geode project log file redaction of sensitive information vulnerability7.5
- CVE-2019-10091When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This co...7.4
- CVE-2017-15694When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cluster metadata. A malicious user could...6.5
- CVE-2017-15695When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode function. This a...8.8
- CVE-2017-15692In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they may be able to cau...9.8
- CVE-2017-15693In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objects to be deserialized. A user with DAT...7.5
- CVE-2017-15696When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gain...7.5
- CVE-2017-9796When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind...5.3
- CVE-2017-9795When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries that allow read and write access t...7.5
- CVE-2017-12622When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status informa...7.1
- CVE-2017-9797When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations coul...6.5
Product grouping is registry-driven, with AI assist and human review. How it works