Описание
GeoServer is an open source server that allows users to share and edit geospatial data. Starting in version 2.10.0 and prior to versions 2.24.4 and 2.25.1, GeoServer's Server Status page and REST API lists all environment variables and Java properties to any GeoServer user with administrative rights as part of those modules' status message. These variables/properties can also contain sensitive information, such as database passwords or API keys/tokens. Additionally, many community-developed GeoServer container images export other credentials from their start-up scripts as environment variables to the GeoServer (java) process. The precise scope of the issue depends on which container image is used and how it is configured.
The about status API endpoint which powers the Server Status page is only available to administrators.Depending on the operating environment, administrators might have legitimate access to credentials in other ways, but this issue defeats more sophisticated con
Уязвимые конфигурации
Одно из
EPSS
4.5 Medium
CVSS3
4.9 Medium
CVSS3
Дефекты
Связанные уязвимости
GeoServer's Server Status shows sensitive environmental variables and Java properties
EPSS
4.5 Medium
CVSS3
4.9 Medium
CVSS3