Skip to content

Commit ebd3882

Browse files
committed
corrections and clarifications
1 parent 8a78c35 commit ebd3882

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

_posts/2025-06-10-cve-disclosure.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ categories:
1010
The GeoServer community has readied the following CVE vulnerabilities for public disclosure.
1111

1212
* [CVE-2025-30220](https://github.com/geoserver/geoserver/security/advisories/GHSA-jj54-8f66-c5pc) XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service (High)
13-
Fixed: 2.27.1 | 2.26.3 | 2.25.6
13+
Fixed: 2.27.1 | 2.26.3 | 2.25.7
1414

1515
* [CVE-2025-30145](https://github.com/geoserver/geoserver/security/advisories/GHSA-gr67-pwcv-76gf) Denial-of-service (DoS) Vulnerability in Jiffle process (High)
1616
Fixed: 2.27.0 | 2.26.3 | 2.25.7
@@ -30,6 +30,8 @@ The GeoServer community has readied the following CVE vulnerabilities for public
3030
* [CVE-2024-29198](https://github.com/geoserver/geoserver/security/advisories/GHSA-5gw5-jccf-6hxw) Unauthenticated SSRF via TestWfsPost (High)
3131
[CVE-2021-40822](https://github.com/geoserver/geoserver/security/advisories/GHSA-68cf-j696-wvv9) SSRF in TestWfsPost for specific targets, e.g. PHP + Nginx (High)
3232
Fixed: 2.25.2 | 2.24.4
33+
34+
This duplication is due to CVE-2021-40822 being generated prior to our use of CVE records.
3335

3436

3537
The following release announcements have been updated:

0 commit comments

Comments
 (0)