{"id":"GHSA-w595-4975-gm3h","summary":"Apache Geode web-api is vulnerable to Cross-site Scripting","details":"Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a logged-in user into clicking a specially-crafted link to execute code on the returned page, which could lead to theft of the user's session information and even account takeover.\n\n\n\nThis issue affects Apache Geode: all versions prior to 1.15.2.\n\nUsers are recommended to upgrade to version 1.15.2, which fixes the issue.","aliases":["CVE-2024-44088"],"modified":"2025-11-05T20:53:08.185359Z","published":"2025-10-14T15:31:27Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-10-14T20:29:02Z","nvd_published_at":"2025-10-14T15:16:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-44088"},{"type":"PACKAGE","url":"https://github.com/apache/geode"},{"type":"WEB","url":"https://lists.apache.org/thread/161r34nokmcc0w74mnf04lskgb8g1d3g"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/10/14/5"}],"affected":[{"package":{"name":"org.apache.geode:geode-web-api","ecosystem":"Maven","purl":"pkg:maven/org.apache.geode/geode-web-api"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.1.0"},{"fixed":"1.15.2"}]}],"versions":["1.1.0","1.1.1","1.10.0","1.11.0","1.12.0","1.12.1","1.12.2","1.12.3","1.12.4","1.12.5","1.12.6","1.12.7","1.12.8","1.12.9","1.13.0","1.13.1","1.13.2","1.13.3","1.13.4","1.13.5","1.13.6","1.13.7","1.13.8","1.14.0","1.14.1","1.14.2","1.14.3","1.14.4","1.15.0","1.15.1","1.2.0","1.2.1","1.3.0","1.4.0","1.5.0","1.6.0","1.7.0","1.8.0","1.9.0","1.9.1","1.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-w595-4975-gm3h/GHSA-w595-4975-gm3h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}