CVE-2024-35230

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Dec 16, 2024
Updated: Dec 17, 2024
CWE ID 200

Summary

CVE-2024-35230 is a vulnerability affecting GeoServer, an open-source Java-based geospatial software server. In susceptible versions, the welcome and about pages unintentionally disclose sensitive information, including software version and revision details, and associated library and component versions. This data exposure poses a security risk because it facilitates the identification of utilized software. The vulnerability has been addressed in GeoServer version 2.26.0. It is recommended that all users upgrade to this version to mitigate the risk. At present, there are no known workarounds for this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share