QID 730772
Date Published: 2023-04-05
QID 730772: GeoServer Insecure Deserialization Vulnerability (GHSA-4pm3-f52j-8ggh)
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.
The GeoServer security mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code execution.
Affected Versions:
GeoServer versions prior to 2.19.6
GeoServer versions from 2.20.0 and prior to version 2.20.4
QID Detection Logic (Unauthenticated): This QID checks for vulnerable GeoServer versions by extracting the version from webpage.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code on the target system.
Solution
Vendor has released patches. For more information please refer to GHSA-4pm3-f52j-8ggh
Vendor References
- GHSA-4pm3-f52j-8ggh -
github.com/geoserver/geoserver/security/advisories/GHSA-4pm3-f52j-8ggh
CVEs related to QID 730772
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4pm3-f52j-8ggh |
|