CVE-2023-25157

Scores

EPSS

0.940high94.0%
0%20%40%60%80%100%

Percentile: 94.0%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service (WMS) protocols. CQL is also supported through the Web Coverage Service (WCS) protocol for ImageMosaic coverages. Users are advised to upgrade to either version 2.21.4, or version 2.22.2 to resolve this issue. Users unable to upgrade should disable the PostGIS Datastore encode functions setting to mitigate strEndsWith, strStartsWith and PropertyIsLike misuse and enable the PostGIS DataStore preparedStatements setting to mitigate the FeatureId misuse.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-89

Related Vulnerabilities

Exploits

Exploit ID: CVE-2023-25157

Source: github-poc

URL: https://github.com/charis3306/CVE-2023-25157

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: geoserver

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",      "versionEndExcluding": "2.18.7",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:osgeo:...

Source: nvd

End of list