GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpServletRequest, HttpServletResponse) has no check to hide potentially sensitive information from users except for a hidden system property to hide the storage locations that defaults to showing the locations. This vulnerability is fixed in 2.26.2 and 2.25.6.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/geoserver/geoserver/security/advisories/GHSA-jm79-7xhw-6f6f | exploit third party advisory |
https://github.com/GeoWebCache/geowebcache/issues/1344 | issue tracking |
https://github.com/GeoWebCache/geowebcache/pull/1345 | patch |
https://github.com/geoserver/geoserver/pull/8189 | patch |
https://osgeo-org.atlassian.net/browse/GEOS-11677 | issue tracking patch |