VYPR

Geoserver

by Geoserver

Source repositories

CVEs (33)

  • CVE-2024-40625MedJun 10, 2025
    risk 0.29cvss 5.5epss 0.00

    GeoServer is an open source server that allows users to share and edit geospatial data. The Coverage rest api /workspaces/{workspaceName}/coveragestores/{storeName}/{method}.{format} allows attackers to upload files with a specified url (with {method} equals 'url') with no…

  • CVE-2024-34696MedJul 1, 2024
    risk 0.29cvss 4.5epss 0.00

    GeoServer is an open source server that allows users to share and edit geospatial data. Starting in version 2.10.0 and prior to versions 2.24.4 and 2.25.1, GeoServer's Server Status page and REST API lists all environment variables and Java properties to any GeoServer user with…

  • CVE-2025-27505MedJun 10, 2025
    risk 0.28cvss 5.3epss 0.01

    GeoServer is an open source server that allows users to share and edit geospatial data. It is possible to bypass the default REST API security and access the index page. The REST API security handles rest and its subpaths but not rest with an extension (e.g., rest.html). The…

  • CVE-2024-35230MedDec 16, 2024
    risk 0.28cvss 5.3epss 0.01

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affected versions the welcome and about page includes version and revision information about the software in use (including library and components used). This…

  • CVE-2024-38524MedJun 10, 2025
    risk 0.27cvss 5.3epss 0.00

    GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpServletRequest, HttpServletResponse) has no check to hide potentially sensitive information from users except for a hidden system…

  • CVE-2024-23821MedMar 20, 2024
    risk 0.24cvss 4.8epss 0.00

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.23.4 and 2.24.1 that enables an authenticated administrator with workspace-level…

  • CVE-2024-23819MedMar 20, 2024
    risk 0.24cvss 4.8epss 0.00

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.23.4 and 2.24.1 that enables an authenticated administrator with workspace-level…

  • CVE-2024-23818MedMar 20, 2024
    risk 0.24cvss 4.8epss 0.00

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.23.3 and 2.24.1 that enables an authenticated administrator with workspace-level…

  • CVE-2024-23643MedMar 20, 2024
    risk 0.24cvss 4.8epss 0.00

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.23.2 and 2.24.1 that enables an authenticated administrator with workspace-level…

  • CVE-2024-23642MedMar 20, 2024
    risk 0.24cvss 4.8epss 0.00

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.23.4 and 2.24.1 that enables an authenticated administrator with workspace-level…

  • CVE-2024-23640MedMar 20, 2024
    risk 0.24cvss 4.8epss 0.00

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.23.3 and 2.24.0 that enables an authenticated administrator with workspace-level…

  • CVE-2023-51445MedMar 20, 2024
    risk 0.24cvss 4.8epss 0.00

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.23.3 and 2.24.0 that enables an authenticated administrator with workspace-level…

  • CVE-2008-7227Sep 14, 2009
    risk 0.00cvss epss 0.01

    PartialBufferOutputStream2 in GeoServer before 1.6.1 and 1.7.0-beta1 attempts to flush buffer contents even when it is handling an "in memory buffer," which prevents the reporting of a service exception, with unknown impact and attack vectors.

Page 2 of 2