GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It possible to achieve Service Side Request Forgery (SSRF) via the Demo request endpoint if Proxy Base URL has not been set. Upgrading to GeoServer 2.24.4, or 2.25.2, removes the TestWfsPost servlet resolving this issue.
History

Tue, 17 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Jun 2025 14:45:00 +0000

Type Values Removed Values Added
Description GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It possible to achieve Service Side Request Forgery (SSRF) via the Demo request endpoint if Proxy Base URL has not been set. Upgrading to GeoServer 2.24.4, or 2.25.2, removes the TestWfsPost servlet resolving this issue.
Title GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-10T14:27:39.485Z

Updated: 2025-06-17T19:12:00.664Z

Reserved: 2024-03-18T17:07:00.095Z

Link: CVE-2024-29198

cve-icon Vulnrichment

Updated: 2025-06-10T14:34:59.250Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-10T15:15:22.140

Modified: 2025-06-12T16:06:39.330

Link: CVE-2024-29198

cve-icon Redhat

No data.