Geode
Vendor:
First CVE: Apr 4, 2017 · Active for 9 years
23
Total CVEs
More Total CVEs than 95% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 61% of tracked products
8.7%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Geode over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 4, 2017
9 years ago
Most Recent CVE
Oct 18, 2025
279 days ago
CVE Severity & Scoring
Geode23 CVEs
30%
48%
22%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.3%)
Network22 (95.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (78.3%)
High5 (21.7%)
Unknown0 (0.0%)
User Interaction
None19 (82.6%)
Unknown0 (0.0%)
Required4 (17.4%)
Privileges Required
Low10 (43.5%)
High0 (0.0%)
None13 (56.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-1938CRITICAL When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e | Feb 24, 2020 | 9.8 | 99 | YES | YES |
CVE-2019-15752HIGH Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\ve | Aug 28, 2019 | 7.8 | 88 | YES | YES |
CVE-2019-14892CRITICAL A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-con | Mar 2, 2020 | 9.8 | 33 | NO | NO |
CVE-2014-0048CRITICAL An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways. | Jan 2, 2020 | 9.8 | 33 | NO | NO |
CVE-2022-37021CRITICAL Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wis | Aug 31, 2022 | 9.8 | 31 | NO | NO |
CVE-2017-15692CRITICAL In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they m | Feb 27, 2018 | 9.8 | 30 | NO | NO |
CVE-2025-47410HIGH Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their G | Oct 18, 2025 | 8.8 | 28 | NO | NO |
CVE-2022-37022HIGH Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user wishing to protect against des | Aug 31, 2022 | 8.8 | 28 | NO | NO |
CVE-2017-15695HIGH When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode | Jun 13, 2018 | 8.8 | 27 | NO | NO |
CVE-2017-5649HIGH Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ but not DATA:READ permi | Apr 4, 2017 | 7.5 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
2 CVEs
8.7% of CVEs· 97th percentile
Metasploit
2 CVEs
8.7% of CVEs· 97th percentile
Nuclei
1 CVE
4.3% of CVEs· 97th percentile
ExploitDB
2 CVEs
8.7% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Geode
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.9.0 | 1 | 7.4 | 1.4% | 0 | 0 |
| 1.14.0 | 1 | 9.8 | 2.4% | 0 | 0 |
| 1.12.0 | 4 | 9.3 | 35.3% | 2 | 2 |