CVE-2025-30145 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

GeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be executed by GeoServer, either as a rende…
High CVSS: 7.5

CVE-2025-30145

GeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be executed by GeoServer, either as a rendering transformation in WMS dynamic styles or as a WPS process, that can enter an infinite loop to trigger denial of service. This vulnerability is fixed in 2.27.0, 2.26.3, and 2.25.7. This vulnerability can be mitigated by disabling WMS dynamic styling and the Jiffle process.
Vendor
Osgeo
Product
Geoserver
CWE
CWE-835
Yayın Tarihi
2025-06-10 15:15:24
Güncelleme
2025-08-26 16:11:23
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar