Description
GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpServletRequest, HttpServletResponse) has no check to hide potentially sensitive information from users except for a hidden system property to hide the storage locations that defaults to showing the locations. This vulnerability is fixed in 2.26.2 and 2.25.6.
Problem types
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Product status
< 2.25.6
References
github.com/...server/security/advisories/GHSA-jm79-7xhw-6f6f
github.com/GeoWebCache/geowebcache/issues/1344
github.com/GeoWebCache/geowebcache/pull/1345
github.com/geoserver/geoserver/pull/8189
osgeo-org.atlassian.net/browse/GEOS-11677