Skip to content

Commit a6fcf5c

Browse files
committed
sorry one more change to disclosure order to align with release order
1 parent cf4d3e4 commit a6fcf5c

File tree

1 file changed

+2
-3
lines changed

1 file changed

+2
-3
lines changed

_posts/2025-06-10-cve-disclosure.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -24,15 +24,14 @@ The GeoServer community has readied the following CVE vulnerabilities for public
2424
* [CVE-2024-40625](https://github.com/geoserver/geoserver/security/advisories/GHSA-r4hf-r8gj-jgw2) Coverage REST API Server Side Request Forgery (Moderate)
2525
Fixed: 2.26.0
2626

27-
* [CVE-2024-34711](https://github.com/geoserver/geoserver/security/advisories/GHSA-mc43-4fqr-c965) Improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF) (High)
28-
Fixed: 2.25.0
29-
3027
* [CVE-2024-29198](https://github.com/geoserver/geoserver/security/advisories/GHSA-5gw5-jccf-6hxw) Unauthenticated SSRF via TestWfsPost (High)
3128
[CVE-2021-40822](https://github.com/geoserver/geoserver/security/advisories/GHSA-68cf-j696-wvv9) SSRF in TestWfsPost for specific targets, e.g. PHP + Nginx (High)
3229
Fixed: 2.25.2 | 2.24.4
3330

3431
This duplication is due to CVE-2021-40822 being generated prior to our use of CVE records.
3532

33+
* [CVE-2024-34711](https://github.com/geoserver/geoserver/security/advisories/GHSA-mc43-4fqr-c965) Improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF) (High)
34+
Fixed: 2.25.0
3635

3736
The following release announcements have been updated:
3837

0 commit comments

Comments
 (0)