GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It possible to achieve Service Side Request Forgery (SSRF) via the Demo request endpoint if Proxy Base URL has not been set. Upgrading to GeoServer 2.24.4, or 2.25.2, removes the TestWfsPost servlet resolving this issue.
References
Link | Resource |
---|---|
https://github.com/geoserver/geoserver/security/advisories/GHSA-5gw5-jccf-6hxw | Mitigation Third Party Advisory |
https://osgeo-org.atlassian.net/browse/GEOS-11390 | Issue Tracking |
https://osgeo-org.atlassian.net/browse/GEOS-11794 | Permissions Required |
Configurations
Configuration 1 (hide)
|
History
26 Aug 2025, 16:25
Type | Values Removed | Values Added |
---|---|---|
First Time |
Osgeo geoserver
Osgeo |
|
CPE | cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:* | |
References | () https://github.com/geoserver/geoserver/security/advisories/GHSA-5gw5-jccf-6hxw - Mitigation, Third Party Advisory | |
References | () https://osgeo-org.atlassian.net/browse/GEOS-11390 - Issue Tracking | |
References | () https://osgeo-org.atlassian.net/browse/GEOS-11794 - Permissions Required |
12 Jun 2025, 16:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
10 Jun 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-10 15:15
Updated : 2025-08-26 16:25
NVD link : CVE-2024-29198
Mitre link : CVE-2024-29198
CVE.ORG link : CVE-2024-29198
JSON object : View
Products Affected
osgeo
- geoserver
CWE
CWE-918
Server-Side Request Forgery (SSRF)