VDB
Sign up
MEDIUM5.3

GHSA-6pfc-w86r-54q6

Welcome and About GeoServer pages communicate version and revision information

Quick fix

GHSA-6pfc-w86r-54q6 — org.geoserver.web:gs-web-app: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.25.1</version> for org.geoserver.web:gs-web-app

Details

### Impact

The welcome and about page includes version and revision information about the software in use (including library and components used).

This information is sensitive from a security point of view because it allows software used by the server to be easily identified.

### Proof of Concept

1. Welcome page footer: <img width="432" alt="image" src="https://github.com/geoserver/geoserver/assets/629681/a7fd5151-55d5-432b-9d5d-79136833609f">

2. About page *build information*.

<img width="401" alt="image" src="https://github.com/geoserver/geoserver/assets/629681/59fcd8dd-eaee-4bf8-9578-a2a94b2864db">

### Patches

No patch presently available.

### Workarounds

No workaround available, although the ADMIN_CONSOLE can be disabled completely.

### References

* [About GeoServer](https://docs.geoserver.org/latest/en/user/webadmin/about.html)

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.geoserver.web:gs-web-app
Introduced in: 2.0.0Fixed in: 2.25.1
Fix# pom.xml: bump <version>2.25.1</version> for org.geoserver.web:gs-web-app
Maven/org.geoserver.web:gs-web-core
Introduced in: 2.0.0Fixed in: 2.25.1
Fix# pom.xml: bump <version>2.25.1</version> for org.geoserver.web:gs-web-core

References