PT-2025-24671 · Geoserver · Geoserver
Sikeoka
·
Published
2025-06-10
·
Updated
2025-07-14
·
CVE-2025-27505
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GeoServer versions prior to 2.25.6
GeoServer versions prior to 2.26.3
Description
The issue allows bypassing the default REST API security, enabling access to the index page. This is possible because the REST API security does not handle 'rest' with an extension (e.g., rest.html). The REST API index can disclose whether certain extensions are installed.
Recommendations
For versions prior to 2.25.6, update to version 2.25.6 or later.
For versions prior to 2.26.3, update to version 2.26.3 or later.
As a temporary workaround, in ${GEOSERVER DATA DIR}/security/config.xml, change the paths for the rest filter to /rest.,/rest/** and change the paths for the gwc filter to /gwc/rest.,/gwc/rest/** and restart GeoServer.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geoserver