Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 Maven

Welcome and About GeoServer pages communicate version and revision information

GHSA-6pfc-w86r-54q6 · CVE-2024-35230

Published · Modified

Description

Impact

The welcome and about page includes version and revision information about the software in use (including library and components used).

This information is sensitive from a security point of view because it allows software used by the server to be easily identified.

Proof of Concept

  1. Welcome page footer:

    image
  2. About page build information.

    image

Patches

No patch presently available.

Workarounds

No workaround available, although the ADMIN_CONSOLE can be disabled completely.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes