PT-2025-24660 · Geoserver · Geoserver

CVE-2024-29198

·

Publicado

2025-06-10

·

Atualizado

2025-07-17

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions GeoServer versions prior to 2.24.4 GeoServer versions prior to 2.25.2
Description The issue allows for Service Side Request Forgery (SSRF) via the Demo request endpoint if the Proxy Base URL has not been set. This can be used by an unauthenticated user to enumerate internal networks and obtain sensitive data, particularly in cloud instances. The TestWfsPost servlet is involved in this issue.
Recommendations For GeoServer versions prior to 2.24.4, upgrade to GeoServer 2.24.4 to remove the TestWfsPost servlet and resolve the issue. For GeoServer versions prior to 2.25.2, upgrade to GeoServer 2.25.2 to remove the TestWfsPost servlet and resolve the issue. As a temporary workaround, consider setting the PROXY BASE URL property to a non-empty value that cannot be overridden by the user interface or incoming request when using GeoServer with a proxy. When using GeoServer directly without a proxy, block all access to TestWfsPost by editing the web.xml file to add a security constraint that blocks access to the /TestWfsPost/* URL pattern.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-10403
CVE-2024-29198
GHSA-5GW5-JCCF-6HXW

Produtos afetados

Geoserver