CVE-2023-51444

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Mar 20, 2024
CWE ID 434
CWE ID 20

Summary

CVE-2023-51444 is an arbitrary file upload vulnerability that affects versions prior to 2.23.4 and 2.24.1 of GeoServer, an open source software server used for sharing and editing geospatial data. This vulnerability allows an authenticated administrator with permissions to modify coverage stores through the REST Coverage Store API to upload arbitrary file contents to arbitrary file locations, leading to remote code execution. The issue arises when coverage stores are configured using absolute paths, which do not prevent path traversal. Exploiting this vulnerability can result in executing arbitrary code or overwriting GeoServer security files, potentially granting full administrator privileges. The fix for this issue is included in versions 2.23.4 and 2.24.1, and organizations should update their GeoServer installations to these versions to remediate the vulnerability.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-51444 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options