Skip to content

Commit cf4d3e4

Browse files
committed
chagne disclosure order to be based release
Still a little hard to read, in order to identify older releases that are not fully patched
1 parent ebd3882 commit cf4d3e4

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

_posts/2025-06-10-cve-disclosure.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -18,12 +18,12 @@ The GeoServer community has readied the following CVE vulnerabilities for public
1818
* [CVE-2025-27505](https://github.com/geoserver/geoserver/security/advisories/GHSA-h86g-x8mm-78m5) Missing Authorization on REST API Index (Moderate)
1919
Fixed: 2.26.3 | 2.25.6
2020

21-
* [CVE-2024-40625](https://github.com/geoserver/geoserver/security/advisories/GHSA-r4hf-r8gj-jgw2) Coverage REST API Server Side Request Forgery (Moderate)
22-
Fixed: 2.26.0
23-
2421
* [CVE-2024-38524](https://github.com/geoserver/geoserver/security/advisories/GHSA-jm79-7xhw-6f6f) GWC Home Page exposes sensitive server information (Moderate)
2522
Fixed: 2.26.2 | 2.25.6
2623

24+
* [CVE-2024-40625](https://github.com/geoserver/geoserver/security/advisories/GHSA-r4hf-r8gj-jgw2) Coverage REST API Server Side Request Forgery (Moderate)
25+
Fixed: 2.26.0
26+
2727
* [CVE-2024-34711](https://github.com/geoserver/geoserver/security/advisories/GHSA-mc43-4fqr-c965) Improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF) (High)
2828
Fixed: 2.25.0
2929

0 commit comments

Comments
 (0)