GeoServer is an open source server that allows users to share and edit geospatial data. The Coverage rest api /workspaces/{workspaceName}/coveragestores/{storeName}/{method}.{format} allows attackers to upload files with a specified url (with {method} equals 'url') with no restrict. This vulnerability is fixed in 2.26.0.
References
Link | Resource |
---|---|
https://github.com/geoserver/geoserver/security/advisories/GHSA-r4hf-r8gj-jgw2 | Third Party Advisory |
https://osgeo-org.atlassian.net/browse/GEOS-11468 | Issue Tracking Patch |
https://osgeo-org.atlassian.net/browse/GEOS-11717 | Permissions Required |
Configurations
History
26 Aug 2025, 16:22
Type | Values Removed | Values Added |
---|---|---|
First Time |
Osgeo geoserver
Osgeo |
|
CPE | cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:* | |
References | () https://github.com/geoserver/geoserver/security/advisories/GHSA-r4hf-r8gj-jgw2 - Third Party Advisory | |
References | () https://osgeo-org.atlassian.net/browse/GEOS-11468 - Issue Tracking, Patch | |
References | () https://osgeo-org.atlassian.net/browse/GEOS-11717 - Permissions Required |
12 Jun 2025, 16:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
10 Jun 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-10 15:15
Updated : 2025-08-26 16:22
NVD link : CVE-2024-40625
Mitre link : CVE-2024-40625
CVE.ORG link : CVE-2024-40625
JSON object : View
Products Affected
osgeo
- geoserver
CWE
CWE-918
Server-Side Request Forgery (SSRF)