Executive brief
GeoServer, a platform for sharing geospatial data, contains a security flaw in its administrative web interface. An authorized administrator could exploit this to create files on the server containing the system's master password in plain text. This could lead to full system compromise, unauthorized data access, or the execution of malicious code if the server is configured to run dynamic web scripts.
Technical details
An arbitrary file write vulnerability exists in GeoServer's Master Password Dump web page due to insufficient validation of user-supplied file paths. While relative path traversal is blocked by previous fixes, the component accepts absolute paths (CWE-73) to create new files. An authenticated administrator with security system access can specify an absolute path to a non-existent file in an existing directory, causing GeoServer to write the master password in plaintext to that location. If the environment allows dynamic deployment (e.g., a default Tomcat installation), an attacker can embed malicious code in the password field and dump it into a JSP file to achieve Remote Code Execution (RCE). The vulnerability is patched in versions 2.26.4 and 2.27.3.
Affected products
- GeoServer gs-web-app < 2.26.4, >= 2.27.0, < 2.27.3
- GeoServer gs-web-sec-core < 2.26.4, >= 2.27.0, < 2.27.3
Timeline
- 2025-06-02: other: Initial pull request to remove the vulnerable page submitted
- 2025-08-28: patched: Fix merged into main branch
- 2026-06-11: advisory: GitHub Security Advisory published
- 2026-06-18: disclosed: CVE published to NVD