QID 997786
Date Published: 2024-03-21
QID 997786: Java (Maven) Security Update for org.geoserver:gs-wms (GHSA-fg9v-56hw-g525)
A stored cross-site scripting (XSS) vulnerability exists that enables an authenticated administrator with workspace-level privileges to store a JavaScript payload in the GeoServer catalog that will execute in the context of another user's browser when viewed in the WMS GetMap SVG Output Format when the Simple SVG renderer is enabled. Access to the WMS SVG Format is available to all users by default although data and service security may limit users' ability to trigger the XSS.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-fg9v-56hw-g525 for updates and patch information.
Vendor References
- GHSA-fg9v-56hw-g525 -
github.com/advisories/GHSA-fg9v-56hw-g525
CVEs related to QID 997786
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fg9v-56hw-g525 | org.geoserver:gs-wms |
|