SCA: security update for org.geoserver:gs-platform, org.geoserver:gs-restconfig (GHSA-9v5q-2gwq-q9hq)

high Tenable Self-Hosted Container Security Plugin ID 413462

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- GeoServer is an open source software server written in Java that allows users to share and edit geospatial
data. An arbitrary file upload vulnerability exists in versions prior to 2.23.4 and 2.24.1 that enables an
authenticated administrator with permissions to modify coverage stores through the REST Coverage Store API
to upload arbitrary file contents to arbitrary file locations which can lead to remote code execution.
Coverage stores that are configured using relative paths use a GeoServer Resource implementation that has
validation to prevent path traversal but coverage stores that are configured using absolute paths use a
different Resource implementation that does not prevent path traversal. This vulnerability can lead to
executing arbitrary code. An administrator with limited privileges could also potentially exploit this to
overwrite GeoServer security files and obtain full administrator privileges. Versions 2.23.4 and 2.24.1
contain a fix for this issue. (CVE-2023-51444)

See Also

https://github.com/advisories/GHSA-9v5q-2gwq-q9hq

Plugin Details

Severity: High

ID: 413462

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 8.3

Temporal Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C

CVSS Score Source: CVE-2023-51444

CVSS v3

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/20/2024

Vulnerability Publication Date: 3/20/2024

Reference Information

CVE: CVE-2023-51444