CVE-2023-51444
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2023-51444 is an arbitrary file upload vulnerability that affects versions prior to 2.23.4 and 2.24.1 of GeoServer, an open source software server used for sharing and editing geospatial data. This vulnerability allows an authenticated administrator with permissions to modify coverage stores through the REST Coverage Store API to upload arbitrary file contents to arbitrary file locations, leading to remote code execution. The issue arises when coverage stores are configured using absolute paths, which do not prevent path traversal. Exploiting this vulnerability can result in executing arbitrary code or overwriting GeoServer security files, potentially granting full administrator privileges. The fix for this issue is included in versions 2.23.4 and 2.24.1, and organizations should update their GeoServer installations to these versions to remediate the vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Advisories, Assessments, and Mitigations
Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future
- Gain complete coverage of your cyber, third party, and physical attack surface
- Proactively mitigate threats before they turn into costly attacks
- Make fast, effective, data-driven decisions