QID 730772

Date Published: 2023-04-05

QID 730772: GeoServer Insecure Deserialization Vulnerability (GHSA-4pm3-f52j-8ggh)

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

The GeoServer security mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code execution.

Affected Versions:
GeoServer versions prior to 2.19.6
GeoServer versions from 2.20.0 and prior to version 2.20.4

QID Detection Logic (Unauthenticated): This QID checks for vulnerable GeoServer versions by extracting the version from webpage.

Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code on the target system.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Vendor has released patches. For more information please refer to GHSA-4pm3-f52j-8ggh

    CVEs related to QID 730772

    Software Advisories
    Advisory ID Software Component Link
    GHSA-4pm3-f52j-8ggh URL Logo github.com/geoserver/geoserver/security/advisories/GHSA-4pm3-f52j-8ggh