{"id":"GHSA-gjp8-99fv-cgcw","summary":"Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system","details":"Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target system on behalf of the authenticated user.\n\n\nThis issue affects Apache Geode: versions 1.10 through 1.15.1\n\nUsers are recommended to upgrade to version 1.15.2, which fixes the issue.","aliases":["CVE-2025-47410"],"modified":"2025-11-05T21:07:47.975817Z","published":"2025-10-18T18:30:22Z","database_specific":{"github_reviewed_at":"2025-10-20T17:55:22Z","nvd_published_at":"2025-10-18T16:15:35Z","cwe_ids":["CWE-352"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47410"},{"type":"WEB","url":"https://github.com/apache/geode/commit/570990909e6fd1e491f01471ad30ee3c2dbff72c"},{"type":"PACKAGE","url":"https://github.com/apache/geode"},{"type":"WEB","url":"https://lists.apache.org/thread/k88tv3rhl4ymsvt4h6qsv7sq10q5prrt"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/10/17/2"}],"affected":[{"package":{"name":"org.apache.geode:geode-web","ecosystem":"Maven","purl":"pkg:maven/org.apache.geode/geode-web"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.10.0"},{"fixed":"1.15.2"}]}],"versions":["1.10.0","1.11.0","1.12.0","1.12.1","1.12.2","1.12.3","1.12.4","1.12.5","1.12.6","1.12.7","1.12.8","1.12.9","1.13.0","1.13.1","1.13.2","1.13.3","1.13.4","1.13.5","1.13.6","1.13.7","1.13.8","1.14.0","1.14.1","1.14.2","1.14.3","1.14.4","1.15.0","1.15.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-gjp8-99fv-cgcw/GHSA-gjp8-99fv-cgcw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}