Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-24749— Classpath resource disclosure in GWC Web Resource API on Windows / Tomcat

Quick assessment

Affected
geoserver geoserver
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GeoServer是一个用 Java 编写的开源软件服务器。允许用户共享和编辑地理空间数据。 GeoServer 存在安全漏洞,该漏洞源于如果使用 Apache Tomcat Web 应用服务器将 GeoServer 部署在 Windows 操作系统中,则可以绕过 GeoWebCache ByteStreamController 类中现有的输入验证并读取具有特定文件扩展名的任意类路径资源。

CVSS 7.5 · High EPSS 0.76% · P54
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-24749

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Classpath resource disclosure in GWC Web Resource API on Windows / Tomcat
Source: CVE Program / CVE List V5
Vulnerability Description
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed in the Windows operating system using an Apache Tomcat web application server, it is possible to bypass existing input validation in the GeoWebCache ByteStreamController class and read arbitrary classpath resources with specific file name extensions. If GeoServer is also deployed as a web archive using the data directory embedded in the `geoserver.war` file (rather than an external data directory), it will likely be possible to read specific resources to gain administrator privileges. However, it is very unlikely that production environments will be using the embedded data directory since, depending on how GeoServer is deployed, it will be erased and re-installed (which would also reset to the default password) either every time the server restarts or every time a new GeoServer WAR is installed and is therefore difficult to maintain. An external data directory will always be used if GeoServer is running in standalone mode (via an installer or a binary). Versions 2.23.5 and 2.24.3 contain a patch for the issue. Some workarounds are available. One may change from a Windows environment to a Linux environment; or change from Apache Tomcat to Jetty application server. One may also disable anonymous access to the embeded GeoWebCache administration and status pages.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5
Vulnerability Title
GeoServer 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GeoServer是一个用 Java 编写的开源软件服务器。允许用户共享和编辑地理空间数据。 GeoServer 存在安全漏洞,该漏洞源于如果使用 Apache Tomcat Web 应用服务器将 GeoServer 部署在 Windows 操作系统中,则可以绕过 GeoWebCache ByteStreamController 类中现有的输入验证并读取具有特定文件扩展名的任意类路径资源。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
geoserver geoserver < 2.23.5 -

II. Public POCs for CVE-2024-24749

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 10654 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2024-24749

请登录查看更多情报信息。

Patches & Fixes for CVE-2024-24749 (2)

Vendor Advisories for CVE-2024-24749 (1)

Same Patch Batch · geoserver · 2024-07-01 · 3 CVEs total

CVE-2024-36401 9.8 CRITICAL Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geose
CVE-2024-34696 4.5 MEDIUM GeoServer's Server Status shows sensitive environmental variables and Java properties

IV. Related Vulnerabilities

V. Comments for CVE-2024-24749

No comments yet


Leave a comment