GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affected versions the welcome and about page includes version and revision information about the software in use (including library and components used). This information is sensitive from a security point of view because it allows software used by the server to be easily identified. This issue has been patched in version 2.26.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/35xxx/CVE-2024-35230.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-200"
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35230.json"
[
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"264390384530364550376415558076538418888",
"66729064145699946270303527886669224462",
"316688617561204369679287933272458214543",
"223475902306217737104071908742842315985",
"159765343543516311903924483963028673775",
"163180396617571576621860191369180988959",
"220001906517579869089548380699027415861",
"177083188573367353303282244393056783537",
"274806334839459561306994181186088457058",
"160581397492471579403230022677133246967"
],
"threshold": 0.9
},
"id": "CVE-2024-35230-539105e0",
"deprecated": false,
"target": {
"file": "src/web/core/src/main/java/org/geoserver/web/AboutGeoServerPage.java"
},
"source": "https://github.com/geoserver/geoserver/commit/8cd1590a604a10875de67b04995f1952f631f920",
"signature_version": "v1"
},
{
"signature_type": "Function",
"digest": {
"length": 6237.0,
"function_hash": "245456823569532183383645347260761842954"
},
"id": "CVE-2024-35230-55c2abd5",
"deprecated": false,
"target": {
"file": "src/web/core/src/main/java/org/geoserver/web/GeoServerBasePage.java",
"function": "commonBaseInit"
},
"source": "https://github.com/geoserver/geoserver/commit/74fdab745a5deff20ac99abca24d8695fe1a52f8",
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"60847058889652797075954759931947206858",
"84127179937111801138315932976355439059",
"16920446801891026294238379234721040863",
"194542924889099744506088167455477306510",
"115024473106098135064762065195539982390",
"22138926825205300270555625814431385949",
"93658810186598002532106046423261084896",
"38292223904079029804271984708945396837",
"84005340830133593640544219567356971992",
"184071169051698821367569521993179555910",
"241892037811870067254430323351462510293"
],
"threshold": 0.9
},
"id": "CVE-2024-35230-566548e0",
"deprecated": false,
"target": {
"file": "src/web/core/src/test/java/org/geoserver/web/GeoServerHomePageTest.java"
},
"source": "https://github.com/geoserver/geoserver/commit/74fdab745a5deff20ac99abca24d8695fe1a52f8",
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"340118808320698307878614231469581158061",
"124089764824999923152934335691122253",
"48886016685142325003055164022199684918",
"316618477686401994484663317971028491805",
"65351695180026130336241994652874130304",
"199996094062521830704208220357282705082"
],
"threshold": 0.9
},
"id": "CVE-2024-35230-75ee90d4",
"deprecated": false,
"target": {
"file": "src/web/core/src/test/java/org/geoserver/web/GeoServerAboutPageTest.java"
},
"source": "https://github.com/geoserver/geoserver/commit/8cd1590a604a10875de67b04995f1952f631f920",
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"82381061740869158764798493510285114385",
"263203556606201036119699334831856786422",
"78043400410493152828614681101709145729",
"148853049548390640772200906876894905488"
],
"threshold": 0.9
},
"id": "CVE-2024-35230-8c3000d7",
"deprecated": false,
"target": {
"file": "src/web/core/src/main/java/org/geoserver/web/GeoServerBasePage.java"
},
"source": "https://github.com/geoserver/geoserver/commit/74fdab745a5deff20ac99abca24d8695fe1a52f8",
"signature_version": "v1"
},
{
"signature_type": "Function",
"digest": {
"length": 358.0,
"function_hash": "288985822217572198861655750705218978232"
},
"id": "CVE-2024-35230-a3d09180",
"deprecated": false,
"target": {
"file": "src/web/core/src/main/java/org/geoserver/web/GeoServerHomePage.java",
"function": "footerMessage"
},
"source": "https://github.com/geoserver/geoserver/commit/74fdab745a5deff20ac99abca24d8695fe1a52f8",
"signature_version": "v1"
},
{
"signature_type": "Function",
"digest": {
"length": 321.0,
"function_hash": "196698984161667706834083241694212143890"
},
"id": "CVE-2024-35230-bfe74264",
"deprecated": false,
"target": {
"file": "src/web/core/src/main/java/org/geoserver/web/AboutGeoServerPage.java",
"function": "AboutGeoServerPage"
},
"source": "https://github.com/geoserver/geoserver/commit/8cd1590a604a10875de67b04995f1952f631f920",
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"95551633061029672999079761429423607737",
"312515336884396830077256815724238704336",
"145047162068370158573824494467340448424"
],
"threshold": 0.9
},
"id": "CVE-2024-35230-d7be4a55",
"deprecated": false,
"target": {
"file": "src/web/core/src/main/java/org/geoserver/web/GeoServerHomePage.java"
},
"source": "https://github.com/geoserver/geoserver/commit/74fdab745a5deff20ac99abca24d8695fe1a52f8",
"signature_version": "v1"
}
]