Back

MEDIUM

GeoServer Stored Cross-Site Scripting (XSS) vulnerability in GWC Seed Form

Published Mar 20, 2024

Description

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.23.2 and 2.24.1 that enables an authenticated administrator with workspace-level privileges to store a JavaScript payload in the GeoServer catalog that will execute in the context of another administrator’s browser when viewed in the GWC Seed Form. Access to the GWC Seed Form is limited to full administrators by default and granting non-administrators access to this endpoint is not recommended. Versions 2.23.2 and 2.24.1 contain a fix for this issue.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Mar 20, 2024
Updated Aug 1, 2024
Reserved Jan 19, 2024
CISA Vulnrichment
Updated Mar 20, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Mar 20, 2024
Updated Aug 1, 2024
Exploited since n/a
EUVD-2024-0824 GHSA-56R3-F536-5GF7