GeoServer是一个用 Java 编写的开源软件服务器。允许用户共享和编辑地理空间数据。 GeoServer 2.23.3 和 2.24.0之前版本存在跨站脚本漏洞,该漏洞源于 REST Resources API 中包含跨站脚本漏洞,允许攻击者将 JavaScript 有效载荷存储在上传的 style/legend资源中,当用户查看 REST Resources API时,在浏览器上下文中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-41877 | 7.2 HIGH | GeoServer log file path traversal vulnerability |
| CVE-2023-51444 | 7.2 HIGH | GeoServer arbitrary file upload vulnerability in REST Coverage Store API |
| CVE-2024-23634 | 6.0 MEDIUM | GeoServer arbitrary file renaming vulnerability in REST Coverage/Data Store API |
| CVE-2024-23640 | 4.8 MEDIUM | GeoServer Stored Cross-Site Scripting (XSS) vulnerability in Style Publisher |
| CVE-2024-23642 | 4.8 MEDIUM | GeoServer Stored Cross-Site Scripting (XSS) vulnerability in Simple SVG Renderer |
| CVE-2024-23643 | 4.8 MEDIUM | GeoServer Stored Cross-Site Scripting (XSS) vulnerability in GWC Seed Form |
| CVE-2024-23818 | 4.8 MEDIUM | GeoServer Stored Cross-Site Scripting (XSS) vulnerability in WMS OpenLayers Format |
| CVE-2024-23821 | 4.8 MEDIUM | GeoServer's GWC Demos Page vulnerable to Stored Cross-Site Scripting (XSS) |
| CVE-2024-23819 | 4.8 MEDIUM | GeoServer Stored Cross-Site Scripting (XSS) vulnerability in MapML HTML Page |
No comments yet