CVE-2025-30220
- EPSS 3.99%
- Veröffentlicht 10.06.2025 15:16:39
- Zuletzt bearbeitet 26.08.2025 16:10:11
GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever expos...
CVE-2025-30145
- EPSS 0.06%
- Veröffentlicht 10.06.2025 14:58:48
- Zuletzt bearbeitet 26.08.2025 16:11:23
GeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be executed by GeoServer, either as a rendering transformation in WMS dynamic styles or as a WPS process, that can enter an infinite ...
CVE-2025-27505
- EPSS 0.58%
- Veröffentlicht 10.06.2025 14:52:19
- Zuletzt bearbeitet 26.08.2025 16:11:55
GeoServer is an open source server that allows users to share and edit geospatial data. It is possible to bypass the default REST API security and access the index page. The REST API security handles rest and its subpaths but not rest with an extensi...
CVE-2024-40625
- EPSS 0.03%
- Veröffentlicht 10.06.2025 14:49:05
- Zuletzt bearbeitet 26.08.2025 16:22:20
GeoServer is an open source server that allows users to share and edit geospatial data. The Coverage rest api /workspaces/{workspaceName}/coveragestores/{storeName}/{method}.{format} allows attackers to upload files with a specified url (with {method...
CVE-2024-38524
- EPSS 0.06%
- Veröffentlicht 10.06.2025 14:43:04
- Zuletzt bearbeitet 26.08.2025 16:22:42
GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpServletRequest, HttpServletResponse) has no check to hide potentially sensitive information from users e...
CVE-2024-34711
- EPSS 0.05%
- Veröffentlicht 10.06.2025 14:33:18
- Zuletzt bearbeitet 26.08.2025 16:24:18
GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables an unauthorized attacker to perform XML External Entities (XEE) attack, then send GET request to any ...
CVE-2024-29198
- EPSS 5%
- Veröffentlicht 10.06.2025 14:27:39
- Zuletzt bearbeitet 26.08.2025 16:25:00
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It possible to achieve Service Side Request Forgery (SSRF) via the Demo request endpoint if Proxy Base URL has not been set. Upgrading to...
CVE-2024-35230
- EPSS 0.21%
- Veröffentlicht 16.12.2024 23:15:06
- Zuletzt bearbeitet 26.08.2025 16:48:42
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affected versions the welcome and about page includes version and revision information about the software in use (including library an...
CVE-2023-43795
- EPSS 90%
- Veröffentlicht 25.10.2023 18:17:32
- Zuletzt bearbeitet 21.11.2024 08:24:48
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to process information from any server using GET and POST requests. This p...
CVE-2023-41339
- EPSS 0.13%
- Veröffentlicht 25.10.2023 18:17:30
- Zuletzt bearbeitet 21.11.2024 08:21:06
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The WMS specification defines an ``sld=<url>`` parameter for GetMap, GetLegendGraphic and GetFeatureInfo operations for user supplied "dy...