Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-44088

Apache Geode: reflected cross-site scripting in the REST web API

Technology

GemFire / Geode

CVSS Score

6.1 / 10.0

Affected Versions

Apache Geode 1.1.0 to 1.15.1

Upstream Fix

1.15.2

Published

October 14, 2025

OSSeva Coverage

Fixed upstream

Description

The REST web API reflects input into its responses, so an attacker who tricks a logged-in user into clicking a crafted link can run script in the returned page, which can lead to session theft and account takeover. The 6.1 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your GemFire / Geode deployment affected?

If you're running Apache Geode 1.1.0 to 1.15.1, you need this patch. Book a discovery call to get covered.