Vulnerabilidades en GeoServer

31 resultados
Análisis Vexday

GeoServer apresenta um perfil de risco mínimo na base Vexday com apenas 1 CVE registrado, sem evidências de exploração ativa em campo. A vulnerabilidade não é crítica e não foi publicada recentemente, sugerindo que o risco imediato é baixo, embora recomenda-se manter monitoramento contínuo dado o histórico de produtos geoespaciais em ambiente de rede.

CVE-2024-36401CRITICALRemote Code Execution (RCE) vulnerability in evaluating property name expressions in GeoserverEPSS 99.8%KEVCVE-2023-25157CRITICALUnfiltered SQL Injection Vulnerabilities in GeoserverEPSS 85.2%CVE-2023-43795HIGHWPS Server Side Request Forgery in GeoServerEPSS 67.7%CVE-2025-58360HIGHGeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap featureEPSS 64.9%KEVCVE-2025-30220CRITICALGeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handlingEPSS 56.7%CVE-2024-29198HIGHGeoServer Vulnerable to Unauthenticated SSRF via TestWfsPostEPSS 2.0%CVE-2023-51444HIGHGeoServer arbitrary file upload vulnerability in REST Coverage Store APIEPSS 1.9%CVE-2022-24847HIGHImproper Input Validation in GeoServerEPSS 1.5%CVE-2025-27511HIGHGeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store ConnectionEPSS 1.1%CVE-2025-27505MEDIUMGeoServer Missing Authorization on REST API IndexEPSS 1.0%CVE-2023-5786MEDIUMGeoServer GeoWebCache rest.html direct requestEPSS 0.8%CVE-2023-41877HIGHGeoServer log file path traversal vulnerabilityEPSS 0.8%CVE-2024-24749HIGHClasspath resource disclosure in GWC Web Resource API on Windows / TomcatEPSS 0.8%CVE-2024-35230MEDIUMWelcome and About GeoServer pages communicate version and revision informationEPSS 0.7%CVE-2024-23634MEDIUMGeoServer arbitrary file renaming vulnerability in REST Coverage/Data Store APIEPSS 0.7%CVE-2025-52465HIGHGeoServer has an arbitrary file write vulnerability in its Master Password Dump PageEPSS 0.6%CVE-2023-41339HIGHUnsecured WMS dynamic styling sld=<url> parameter affords blind unauthenticated SSRF in GeoServerEPSS 0.5%CVE-2023-51445MEDIUMGeoServer Stored Cross-Site Scripting (XSS) vulnerability in REST Resources APIEPSS 0.5%CVE-2025-30145HIGHGeoServer has an Infinite Loop Vulnerability in Jiffle processEPSS 0.4%CVE-2024-23819MEDIUMGeoServer Stored Cross-Site Scripting (XSS) vulnerability in MapML HTML PageEPSS 0.4%