QID 997789
Date Published: 2024-03-21
QID 997789: Java (Maven) Security Update for org.geoserver:gs-restconfig (GHSA-fh7p-5f6g-vj2w)
A stored cross-site scripting (XSS) vulnerability exists that enables an authenticated administrator with workspace-level privileges to store a JavaScript payload in uploaded style/legend resources that will execute in the context of another administrator's browser when viewed in the REST Resources API. Access to the REST Resources API is limited to full administrators by default and granting non-administrators access to this endpoint should be carefully considered as it may allow access to files containing sensitive information.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-fh7p-5f6g-vj2w for updates and patch information.
Vendor References
- GHSA-fh7p-5f6g-vj2w -
github.com/advisories/GHSA-fh7p-5f6g-vj2w
CVEs related to QID 997789
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fh7p-5f6g-vj2w | org.geoserver:gs-restconfig |
|