CVE-2024-38524

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
10/06/2025
Last modified:
26/08/2025

Description

GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpServletRequest, HttpServletResponse) has no check to hide potentially sensitive information from users except for a hidden system property to hide the storage locations that defaults to showing the locations. This vulnerability is fixed in 2.26.2 and 2.25.6.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:* 2.25.6 (excluding)
cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:* 2.26.0 (including) 2.26.2 (excluding)