Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-29198


GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It possible to achieve Service Side Request Forgery (SSRF) via the Demo request endpoint if Proxy Base URL has not been set. Upgrading to GeoServer 2.24.4, or 2.25.2, removes the TestWfsPost servlet resolving this issue.


Published

2025-06-10T15:15:22.140

Last Modified

2025-08-26T16:25:00.947

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-918

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application osgeo geoserver < 2.24.4 Yes
Application osgeo geoserver < 2.25.2 Yes

References