QID 150850
Date Published: 2024-04-04
QID 150850: GeoServer Multiple Stored Cross-Site Scripting (XSS) Vulnerabilities (CVE-2024-23642, CVE-2024-23819, CVE-2024-23821)
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.
Multiple Stored Cross-Site Scripting (XSS) Vulnerabilities have been identified in GeoServer:
CVE-2024-23642: Stored Cross-Site Scripting (XSS) vulnerability in Simple SVG Renderer.
CVE-2024-23819: Stored Cross-Site Scripting (XSS) vulnerability in MapML HTML Page.
CVE-2024-23821: Stored Cross-Site Scripting (XSS) vulnerability in GWC Demos Page.
Affected Versions:
GeoServer Versions prior to version 2.23.4
GeoServer Versions prior to version 2.24.1
QID Detection Logic (Unauthenticated):
This QID sends HTTP GET requests and checks for vulnerable version of GeoServer running on the target host.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.
For more information pertaining to these vulnerabilities, please refer following Security Advisories:
CVE-2024-23642
CVE-2024-23819
CVE-2024-23821
For information regarding GeoServer releases, please refer GeoServer Blog.
- GHSA-7x76-57fr-m5r5 -
github.com/geoserver/geoserver/security/advisories/GHSA-7x76-57fr-m5r5 - GHSA-88wc-fcj9-q3r9 -
github.com/geoserver/geoserver/security/advisories/GHSA-88wc-fcj9-q3r9 - GHSA-fg9v-56hw-g525 -
github.com/geoserver/geoserver/security/advisories/GHSA-fg9v-56hw-g525
CVEs related to QID 150850
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7x76-57fr-m5r5 |
|
||
| GHSA-88wc-fcj9-q3r9 |
|
||
| GHSA-fg9v-56hw-g525 |
|