Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2022-34870

Apache Geode: stored cross-site scripting in Pulse region entry views

Technology

GemFire / Geode

CVSS Score

5.4 / 10.0

Affected Versions

Apache Geode 1.15.0 and earlier

Upstream Fix

Geode 1.15.1; GemFire 9.15.3

Published

October 25, 2022

OSSeva Coverage

Fixed upstream

Description

Data injected into region entries is rendered without escaping when viewed in the Pulse web application, allowing stored cross-site scripting. Broadcom lists the fix in Tanzu GemFire 9.15.3.

Upstream record: NVD · CVE.org

Is your GemFire / Geode deployment affected?

If you're running Apache Geode 1.15.0 and earlier, you need this patch. Book a discovery call to get covered.