QID 731288
QID 731288: GeoServer Multiple Security Vulnerabilities (CVE-2024-23821,CVE-2024-23819)
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.
Affected Versions:
GeoServer Versions prior to version 2.23.4 and prior to version 2.24.1
QID Detection Logic (Unauthenticated): This QID checks for vulnerable GeoServer versions by extracting the version from webpage.
Successful exploitation of this vulnerability may allow an authenticated administrator with workspace-level privileges to store a JavaScript payload in the GeoServer catalog.
Solution
Vendor has released patches. For more information please refer to GeoServer 2.23.4 and 2.24.1 or later
Vendor References
- GeoServer Advisory -
github.com/geoserver/geoserver/security/advisories/GHSA-88wc-fcj9-q3r9 - GeoServerrAdvisory -
github.com/geoserver/geoserver/security/advisories/GHSA-7x76-57fr-m5r5
CVEs related to QID 731288
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GeoServer Releases |
|