PT-2025-24660 · Geoserver · Geoserver
CVE-2024-29198
·
Publicado
2025-06-10
·
Atualizado
2025-07-17
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GeoServer versions prior to 2.24.4
GeoServer versions prior to 2.25.2
Description
The issue allows for Service Side Request Forgery (SSRF) via the Demo request endpoint if the Proxy Base URL has not been set. This can be used by an unauthenticated user to enumerate internal networks and obtain sensitive data, particularly in cloud instances. The
TestWfsPost servlet is involved in this issue.Recommendations
For GeoServer versions prior to 2.24.4, upgrade to GeoServer 2.24.4 to remove the
TestWfsPost servlet and resolve the issue.
For GeoServer versions prior to 2.25.2, upgrade to GeoServer 2.25.2 to remove the TestWfsPost servlet and resolve the issue.
As a temporary workaround, consider setting the PROXY BASE URL property to a non-empty value that cannot be overridden by the user interface or incoming request when using GeoServer with a proxy.
When using GeoServer directly without a proxy, block all access to TestWfsPost by editing the web.xml file to add a security constraint that blocks access to the /TestWfsPost/* URL pattern.Exploit
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Geoserver