{"id":"CVE-2022-34870","aliases":["GHSA-373r-9mg8-3jc4"],"url":"https://o3.security/vulnerability/CVE-2022-34870","summary":"Apache Geode stored Cross-Site Scripting (XSS) via data injection vulnerability in Pulse web application","details":"Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse web application to view Region entries.","published":"2022-10-25T00:00:00Z","modified":"2026-08-12T03:51:27.303929400Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.geode:geode-core","fixedVersion":"1.15.1"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.apache.org/thread/zltlr7f2ymr2m6jj54k4z0c4foos5fwx"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/34xxx/CVE-2022-34870.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-34870"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2022/10/24/3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:27.303929400Z"}}