External Control of File Name or Path in geoserver - CVE-2024-23634
Published: March 19, 2024 / Updated: May 5, 2026
geoserver
geoserver
Description
The vulnerability allows a remote user to rename arbitrary files and directories, causing a denial of service.
The vulnerability exists due to external control of file name or path in the REST Coverage Store or Data Store API when using the external upload method. A remote privileged user can send a specially crafted upload request to rename arbitrary files and directories, causing a denial of service.
Successful exploitation is limited to file and directory names that do not end in ".zip".