CVE-2024-34696
Last modified
CVE-2024-34696 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. GeoServer is an open source server that allows users to share and edit geospatial data. Starting in version 2.10.0 and prior to versions 2.24.4 and 2.25.1, GeoServer's Server Status page and REST API lists all environment variables and Java properties to any GeoServer user with administrative rights as part of those modules' status message. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
GeoServer is an open source server that allows users to share and edit geospatial data. Starting in version 2.10.0 and prior to versions 2.24.4 and 2.25.1, GeoServer's Server Status page and REST API lists all environment variables and Java properties to any GeoServer user with administrative rights as part of those modules' status message. These variables/properties can also contain sensitive information, such as database passwords or API keys/tokens. Additionally, many community-developed GeoServer container images `export` other credentials from their start-up scripts as environment variables to the GeoServer (`java`) process. The precise scope of the issue depends on which container image is used and how it is configured. The `about status` API endpoint which powers the Server Status page is only available to administrators.Depending on the operating environment, administrators might have legitimate access to credentials in other ways, but this issue defeats more sophisticated controls (like break-glass access to secrets or role accounts).By default, GeoServer only allows same-origin authenticated API access. This limits the scope for a third-party attacker to use an administrator’s credentials to gain access to credentials. The researchers who found the vulnerability were unable to determine any other conditions under which the GeoServer REST API may be available more broadly. Users should update container images to use GeoServer 2.24.4 or 2.25.1 to get the bug fix. As a workaround, leave environment variables and Java system properties hidden by default. Those who provide the option to re-enable it should communicate the impact and risks so that users can make an informed choice.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Geoserver | Geoserver | >= 2.10.0, < 2.24.4 |
| Geoserver | Geoserver | >= 2.25.0, < 2.25.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-34696?
How severe is CVE-2024-34696?
How do I fix CVE-2024-34696?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-34690SAP Student Life Cycle Management (SLcM) fails to conduct pr…5.4
- CVE-2024-34691Manage Incoming Payment Files (F1680) of SAP S/4HANA does no…6.5
- CVE-2024-34692Due to missing verification of file type or content, SAP Ena…4.6
- CVE-2024-34693Improper Input Validation vulnerability in Apache Superset, …5.3
- CVE-2024-34694LNbits is a Lightning wallet and accounts system. Paying inv…8.1
- CVE-2024-34695WOWS Karma is a reputation system for Wargaming's World of W…6.3
- CVE-2024-34697FreeScout is a free, self-hosted help desk and shared mailbo…6.1
- CVE-2024-34698FreeScout is a free, self-hosted help desk and shared mailbo…6.3
- CVE-2024-34699GZ::CTF is a capture the flag platform. Prior to 0.20.1, unp…6.5
- CVE-2024-3470An Improper Privilege Management vulnerability was identifie…7.2
- CVE-2024-34701CreateWiki is Miraheze's MediaWiki extension for requesting …5.9
- CVE-2024-34702Botan is a C++ cryptography library. X.509 certificates can …5.3
Are you affected by CVE-2024-34696?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
