QID 150853
Date Published: 2024-04-04
QID 150853: GeoServer Multiple Stored Cross-Site Scripting (XSS) Vulnerabilities (CVE-2023-51445, CVE-2024-23640)
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.
Multiple Stored Cross-Site Scripting (XSS) Vulnerabilities have been identified in GeoServer:
CVE-2023-51445: Stored Cross-Site Scripting (XSS) vulnerability in REST Resources API.
CVE-2024-23640: Stored Cross-Site Scripting (XSS) vulnerability in Style Publisher.
Affected Versions:
GeoServer Versions prior to version 2.23.3
QID Detection Logic (Unauthenticated):
This QID sends HTTP GET requests and checks for vulnerable version of GeoServer running on the target host.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.
For more information pertaining to these vulnerabilities, please refer following Security Advisories:
CVE-2023-51445
CVE-2024-23640
For information regarding GeoServer releases, please refer GeoServer Blog.
- GHSA-9rfr-pf2x-g4xf -
github.com/geoserver/geoserver/security/advisories/GHSA-9rfr-pf2x-g4xf - GHSA-fh7p-5f6g-vj2w -
github.com/geoserver/geoserver/security/advisories/GHSA-fh7p-5f6g-vj2w
CVEs related to QID 150853
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9rfr-pf2x-g4xf |
|
||
| GHSA-fh7p-5f6g-vj2w |
|