QID 730774
Date Published: 2023-04-05
QID 730774: GeoServer Memory Corruption Vulnerability
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.
The flush function in GeoServer may allow manipulation with an unknown input leads to a memory corruption vulnerability.
Affected Versions:
GeoServer versions prior to 1.6.1
GeoServer versions 1.7.0-beta1
QID Detection Logic (Unauthenticated): This QID checks for vulnerable GeoServer versions by extracting the version from webpage.
Successful exploitation of this vulnerability may allow an attacker to corrupt memory with malicious input.
Solution
Vendor has released patches. For more information please refer to GeoServer 1.6.1 and 1.7.0-beta1 or later
Vendor References
- GeoServer Releases -
github.com/geoserver/geoserver/releases
CVEs related to QID 730774
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GeoServer Releases |
|