<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 10:43:40 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-10400</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-10400</link>
      <description>bdu:2025-10400</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-10400</guid>
    </item>
    <item>
      <title>EUVD-2026-243632</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-243632</link>
      <description>EUVD-2026-243632</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-243632</guid>
    </item>
    <item>
      <title>fkie_cve-2024-38524</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-38524</link>
      <description>&lt;p&gt;GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpServletRequest, HttpServletResponse) has no check to hide potentially sensitive information from users except for a hidden system property to hide the storage locations that defaults to showing the locations. This vulnerability is fixed in 2.26.2 and 2.25.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpServletRequest, HttpServletResponse) has no check to hide potentially sensitive information from users except for a hidden system property to hide the storage locations that defaults to showing the locations. This vulnerability is fixed in 2.26.2 and 2.25.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-38524</guid>
    </item>
    <item>
      <title>GHSA-jm79-7xhw-6f6f — GWC Home Page communicate version and revision information</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jm79-7xhw-6f6f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.geoserver.web:gs-web-app, Maven: org.geoserver:gs-gwc&lt;/p&gt;
&lt;p&gt;### Summary
The GeoWebCache home page includes version and revision information about the software in use. This information is sensitive from a security point of view because it allows software used by the server to be easily identified.&lt;/p&gt;
&lt;p&gt;### Details
org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpServletRequest, HttpServletResponse) has no check to hide potentially sensitive information from users except for a hidden system property to hide the storage locations that defaults to showing the locations.&lt;/p&gt;
&lt;p&gt;### PoC
Just open http://localhost:8080/geoserver/gwc/&lt;/p&gt;
&lt;p&gt;### Impact
In addition to exposing the version and revision information, the home page will expose the config file and storage locations which may expose the system&amp;#39;s temp directory location and whether or not GeoServer is running in a Windows operating system. The approximate server start time and some basic GWC usage information is also exposed.&lt;/p&gt;
&lt;p&gt;### References
https://osgeo-org.atlassian.net/browse/GEOS-11677
https://github.com/geoserver/geoserver/pull/8189
https://github.com/GeoWebCache/geowebcache/issues/1344
https://github.com/GeoWebCache/geowebcache/pull/1345&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.geoserver.web:gs-web-app, Maven: org.geoserver:gs-gwc&lt;/p&gt;
&lt;p&gt;### Summary
The GeoWebCache home page includes version and revision information about the software in use. This information is sensitive from a security point of view because it allows software used by the server to be easily identified.&lt;/p&gt;
&lt;p&gt;### Details
org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpServletRequest, HttpServletResponse) has no check to hide potentially sensitive information from users except for a hidden system property to hide the storage locations that defaults to showing the locations.&lt;/p&gt;
&lt;p&gt;### PoC
Just open http://localhost:8080/geoserver/gwc/&lt;/p&gt;
&lt;p&gt;### Impact
In addition to exposing the version and revision information, the home page will expose the config file and storage locations which may expose the system&amp;#39;s temp directory location and whether or not GeoServer is running in a Windows operating system. The approximate server start time and some basic GWC usage information is also exposed.&lt;/p&gt;
&lt;p&gt;### References
https://osgeo-org.atlassian.net/browse/GEOS-11677
https://github.com/geoserver/geoserver/pull/8189
https://github.com/GeoWebCache/geowebcache/issues/1344
https://github.com/GeoWebCache/geowebcache/pull/1345&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jm79-7xhw-6f6f</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1267 — GeoServer: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1267</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in GeoServer ausnutzen, um Informationen offenzulegen oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in GeoServer ausnutzen, um Informationen offenzulegen oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1267</guid>
    </item>
  </channel>
</rss>
