github.com
https://github.com/geoserver/geoserver CVE-2024-40625
MEDIUM
GeoServer Coverage REST API Allows Server Side Request Forgery
Record summary
CVE-2024-40625 has a selected CVSS score of 5.5 (medium).
Description
GeoServer is an open source server that allows users to share and edit geospatial data. The Coverage rest api /workspaces/{workspaceName}/coveragestores/{storeName}/{method}.{format} allows attackers to upload files with a specified url (with {method} equals 'url') with no restrict. This vulnerability is fixed in 2.26.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 10, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
geoserverBrowse geoserver / geoserver | CVE List | < 2.26.0 | affected |
org.geoserver.web:gs-web-appBrowse Maven / org.geoserver.web:gs-web-app | GitHub Advisory | Before 2.26.0 · Fixed in 2.26.0 | affected |
org.geoserver:gs-restBrowse Maven / org.geoserver:gs-rest | GitHub Advisory | Before 2.26.0 · Fixed in 2.26.0 | affected |
References
5github.comConfirmation
https://github.com/geoserver/geoserver/security/advisories/GHSA-r4hf-r8gj-jgw2 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-40625 osgeo-org.atlassian.net
https://osgeo-org.atlassian.net/browse/GEOS-11468 osgeo-org.atlassian.net
https://osgeo-org.atlassian.net/browse/GEOS-11717