QID 150854
Date Published: 2024-04-04
QID 150854: GeoServer Arbitrary File Upload Vulnerability (CVE-2023-51444)
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.
An Arbitrary File Upload Vulnerability exists in GeoServer that enables an authenticated administrator with permissions to modify coverage stores through the REST Coverage Store API to upload arbitrary file contents to arbitrary file locations which can lead to remote code execution.
Affected Versions:
GeoServer Versions prior to version 2.23.4
GeoServer Versions prior to version 2.24.1
QID Detection Logic (Unauthenticated):
This QID sends HTTP GET requests and checks for vulnerable version of GeoServer running on the target host.
Successful exploitation of this vulnerability can lead to executing arbitrary code and could allow an administrator with limited privileges to overwrite GeoServer security files and obtain full Administrator privileges.
For more information pertaining to this vulnerability, please refer GitHub Security Advisory.
For information regarding GeoServer releases, please refer GeoServer Blog.
- GHSA-9v5q-2gwq-q9hq -
github.com/geoserver/geoserver/security/advisories/GHSA-9v5q-2gwq-q9hq
CVEs related to QID 150854
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9v5q-2gwq-q9hq |
|