Opened 2 years ago
Last modified 2 years ago
#2420 closed defect
update Geoserver — at Version 1
Reported by: | darkblueb | Owned by: | |
---|---|---|---|
Priority: | critical | Milestone: | OSGeoLive16.0 |
Component: | OSGeoLive | Keywords: | geoserver |
Cc: | osgeolive@… |
Description (last modified by ) ¶
there has been a recent security patch for geoserver
juanluisrpJuanLu: I think it was CVE-2023-25157 OGC Filter SQL Injection Vulnerabilities. The vulnerability applies to any database backend; also any other software using GeoTools (depending on how they use it) can be vulnerable. I think the fixes were backported to some previous versions able to run on Java 8; 2.22.2 has the patch
https://geoserver.org/vulnerability/2023/02/20/ogc-filter-injection.html
Note:
See TracTickets
for help on using tickets.