CVE-2024-44088

CVE-2024-44088: Apache Geode: Reflected XSS

Vendor Apache Software Foundation
Product Apache Geode
Weakness CWE-79 · XSS
Published October 14, 2025
Last update November 4, 2025

CVSS base score

What the vulnerability does

Description

Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a logged-in user into clicking a specially-crafted link to execute code on the returned page, which could lead to theft of the user's session information and even account takeover. This issue affects Apache Geode: all versions prior to 1.15.2 Users are recommended to upgrade to version 1.15.2, which fixes the issue.

Key dates

Disclosure timeline

October 14, 2025 CVE published
November 4, 2025 Record updated