Launch Week Day 1: Announcing Security Design Review
UNKNOWN Maven

PartialBufferOutputStream2 flush issues

GHSA-8hmh-mhqv-7638

Published ยท Modified

Description

Withdrawn

This advisory has been withdrawn as there the effects of the bug would only give the caller an incomplete view of data which they would be authorized to see.

Original Advisory

PartialBufferOutputStream2 in GeoServer before 1.6.1 and 1.7.0-beta1 attempts to flush buffer contents even when it is handling an "in memory buffer," which prevents the reporting of a service exception, with unknown impact and attack vectors.

Ready to move

Start Securing

Free, no credit card | First findings in minutes