Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h86g-x8mm-78m5

Опубликовано: 10 июн. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

GeoServer Missing Authorization on REST API Index

Summary

It is possible to bypass the default REST API security and access the index page.

Details

The REST API security handles rest and its subpaths but not rest with an extension (e.g., rest.html).

Impact

The REST API index can disclose whether certain extensions are installed.

Workaround

In ${GEOSERVER_DATA_DIR}/security/config.xml, change the paths for the rest filter to /rest.*,/rest/** and change the paths for the gwc filter to /gwc/rest.*,/gwc/rest/** and restart GeoServer.

References

https://osgeo-org.atlassian.net/browse/GEOS-11664
https://osgeo-org.atlassian.net/browse/GEOS-11776
https://github.com/geoserver/geoserver/pull/8170

Пакеты

Наименование

org.geoserver.web:gs-web-app

maven
Затронутые версииВерсия исправления

>= 2.26.0, < 2.26.3

2.26.3

Наименование

org.geoserver.web:gs-web-app

maven
Затронутые версииВерсия исправления

< 2.25.6

2.25.6

Наименование

org.geoserver:gs-rest

maven
Затронутые версииВерсия исправления

>= 2.26.0, < 2.26.3

2.26.3

Наименование

org.geoserver:gs-rest

maven
Затронутые версииВерсия исправления

< 2.25.6

2.25.6

EPSS

Процентиль: 61%
0.00408
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.3
nvd
8 месяцев назад

GeoServer is an open source server that allows users to share and edit geospatial data. It is possible to bypass the default REST API security and access the index page. The REST API security handles rest and its subpaths but not rest with an extension (e.g., rest.html). The REST API index can disclose whether certain extensions are installed. This vulnerability is fixed in 2.26.3 and 2.25.6. As a workaround, in ${GEOSERVER_DATA_DIR}/security/config.xml, change the paths for the rest filter to /rest.*,/rest/** and change the paths for the gwc filter to /gwc/rest.*,/gwc/rest/** and restart GeoServer.

EPSS

Процентиль: 61%
0.00408
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862