- Description
- GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service (WMS) protocols. CQL is also supported through the Web Coverage Service (WCS) protocol for ImageMosaic coverages. Users are advised to upgrade to either version 2.21.4, or version 2.22.2 to resolve this issue. Users unable to upgrade should disable the PostGIS Datastore *encode functions* setting to mitigate ``strEndsWith``, ``strStartsWith`` and ``PropertyIsLike `` misuse and enable the PostGIS DataStore *preparedStatements* setting to mitigate the ``FeatureId`` misuse.
- Source
- security-advisories@github.com
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- Hype score
- Not currently trending
CVE-2023-25157 - GeoServer SQL Injection vulnerabilities arise from insufficient sanitization of user input in the CQL_FILTER parameter of WFS and WMS protocols https://t.co/Fwiz8YDlBC
@0x3n0
25 Jan 2025
162 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
As most CVEs we track decrease in scanning, we notice a spike in the scanning of CVE-2023-25157, a critical vulnerability in the GeoServer software project. Review our summary to see what other trends we spotted. https://t.co/ykgZspcIY2 #F5Labs #IoT https://t.co/JJAzuH5hsv
@F5Labs
20 Nov 2024
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CAC1A80B-98D3-4625-8819-EA1B81CE00F8",
"versionEndExcluding": "2.18.7"
},
{
"criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6FA3065D-87A8-4DC1-8E2D-0FFEF02CAC79",
"versionEndExcluding": "2.19.7",
"versionStartIncluding": "2.19.0"
},
{
"criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "10778C77-EB5C-4F66-B915-67BF09BDD364",
"versionEndExcluding": "2.20.7",
"versionStartIncluding": "2.20.0"
},
{
"criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5CDCB1FA-BF94-4CB6-BC14-C38777BCDB89",
"versionEndExcluding": "2.21.4",
"versionStartIncluding": "2.21.0"
},
{
"criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "873D8AE3-D184-486E-86AB-E0D00454C533",
"versionEndExcluding": "2.22.2",
"versionStartIncluding": "2.22.0"
}
],
"operator": "OR"
}
]
}
]