CVE-2024-44088
MEDIUMApache Geode < 1.15.2 - XSS
Title source: ruleDescription
Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a logged-in user into clicking a specially-crafted link to execute code on the returned page, which could lead to theft of the user's session information and even account takeover. This issue affects Apache Geode: all versions prior to 1.15.2 Users are recommended to upgrade to version 1.15.2, which fixes the issue.
Scores
CVSS v3
6.1
EPSS
0.0021
EPSS Percentile
42.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (2)
apache/geode
< 1.15.2
org.apache.geode/geode-web-api
< 1.15.2Maven
Timeline
Published
Oct 14, 2025
Tracked Since
Feb 18, 2026