Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-34696

Опубликовано: 01 июл. 2024
Источник: nvd
CVSS3: 4.5
CVSS3: 4.9
EPSS Низкий

Описание

GeoServer is an open source server that allows users to share and edit geospatial data. Starting in version 2.10.0 and prior to versions 2.24.4 and 2.25.1, GeoServer's Server Status page and REST API lists all environment variables and Java properties to any GeoServer user with administrative rights as part of those modules' status message. These variables/properties can also contain sensitive information, such as database passwords or API keys/tokens. Additionally, many community-developed GeoServer container images export other credentials from their start-up scripts as environment variables to the GeoServer (java) process. The precise scope of the issue depends on which container image is used and how it is configured.

The about status API endpoint which powers the Server Status page is only available to administrators.Depending on the operating environment, administrators might have legitimate access to credentials in other ways, but this issue defeats more sophisticated con

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:geoserver:geoserver:*:*:*:*:*:*:*:*
Версия от 2.10.0 (включая) до 2.24.4 (исключая)
cpe:2.3:a:geoserver:geoserver:*:*:*:*:*:*:*:*
Версия от 2.25.0 (включая) до 2.25.1 (исключая)

EPSS

Процентиль: 61%
0.00418
Низкий

4.5 Medium

CVSS3

4.9 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4.5
github
больше 1 года назад

GeoServer's Server Status shows sensitive environmental variables and Java properties

EPSS

Процентиль: 61%
0.00418
Низкий

4.5 Medium

CVSS3

4.9 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo