Vulnerability Details CVE-2025-47410
Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target system on behalf of the authenticated user.
This issue affects Apache Geode: versions 1.10 through 1.15.1
Users are recommended to upgrade to version 1.15.2, which fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 3.6%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2025-47410
-
cpe:2.3:a:apache:geode:1.10.0
-
cpe:2.3:a:apache:geode:1.11.0
-
cpe:2.3:a:apache:geode:1.12.0
-
cpe:2.3:a:apache:geode:1.12.1
-
cpe:2.3:a:apache:geode:1.12.2
-
cpe:2.3:a:apache:geode:1.12.3
-
cpe:2.3:a:apache:geode:1.12.4
-
cpe:2.3:a:apache:geode:1.12.5
-
cpe:2.3:a:apache:geode:1.12.6
-
cpe:2.3:a:apache:geode:1.12.7
-
cpe:2.3:a:apache:geode:1.12.8
-
cpe:2.3:a:apache:geode:1.12.9
-
cpe:2.3:a:apache:geode:1.13.0
-
cpe:2.3:a:apache:geode:1.13.1
-
cpe:2.3:a:apache:geode:1.13.2
-
cpe:2.3:a:apache:geode:1.13.3
-
cpe:2.3:a:apache:geode:1.13.4
-
cpe:2.3:a:apache:geode:1.13.5
-
cpe:2.3:a:apache:geode:1.13.6
-
cpe:2.3:a:apache:geode:1.13.7
-
cpe:2.3:a:apache:geode:1.13.8
-
cpe:2.3:a:apache:geode:1.14.0
-
cpe:2.3:a:apache:geode:1.14.1
-
cpe:2.3:a:apache:geode:1.14.2
-
cpe:2.3:a:apache:geode:1.14.3
-
cpe:2.3:a:apache:geode:1.14.4
-
cpe:2.3:a:apache:geode:1.15.0
-
cpe:2.3:a:apache:geode:1.15.1