PT-2025-24671 · Geoserver · Geoserver

Sikeoka

·

Published

2025-06-10

·

Updated

2025-07-14

·

CVE-2025-27505

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GeoServer versions prior to 2.25.6 GeoServer versions prior to 2.26.3
Description The issue allows bypassing the default REST API security, enabling access to the index page. This is possible because the REST API security does not handle 'rest' with an extension (e.g., rest.html). The REST API index can disclose whether certain extensions are installed.
Recommendations For versions prior to 2.25.6, update to version 2.25.6 or later. For versions prior to 2.26.3, update to version 2.26.3 or later. As a temporary workaround, in ${GEOSERVER DATA DIR}/security/config.xml, change the paths for the rest filter to /rest.,/rest/** and change the paths for the gwc filter to /gwc/rest.,/gwc/rest/** and restart GeoServer.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27505
GHSA-H86G-X8MM-78M5

Affected Products

Geoserver