We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpServletRequest, HttpServletResponse) has no check to hide potentially sensitive information from users except for a hidden system property to hide the storage locations that defaults to showing the locations. This vulnerability is fixed in 2.26.2 and 2.25.6.
Reserved 2024-06-18 | Published 2025-06-10 | Updated 2025-06-10 | Assigner GitHub_MCWE-200: Exposure of Sensitive Information to an Unauthorized Actor
github.com/...server/security/advisories/GHSA-jm79-7xhw-6f6f
github.com/GeoWebCache/geowebcache/issues/1344
github.com/GeoWebCache/geowebcache/pull/1345
github.com/geoserver/geoserver/pull/8189
osgeo-org.atlassian.net/browse/GEOS-11677
Support options