Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | GeoServer XML±í²¿ÊµÌå×¢Èë·ì϶ |
CVE ID | CVE-2025-58360 |
·ì϶ÀàÐÍ | XXE ×¢Èë | ·¢ÏÖ¹¦·ò | 2025-11-26 |
·ì϶ÆÀ·Ö | 8.2 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
GeoServerÊÇÒ»¸ö¿ªÔ´µÄµØÀíÐÅϢϵͳ£¨GIS£©·þÎñÆ÷£¬ÖØÒªÓÃÓÚ°ä²¼¡¢¹²ÏíºÍ±à×ëµØÀí¿Õ¼äÊý¾Ý¡£ËüÖ§³Ö¶àÖֳ߶ȵÄÊ¢¿ªµØÀíÊý¾ÝÌåʽ£¬Ô̺¬WMS£¨Web Map Service£©¡¢WFS£¨Web Feature Service£©ºÍWCS£¨Web Coverage Service£©£¬¿ÉÄÜÓë¸÷ÀàGIS¿Í»§¶Ë½øÐн»»¥¡£GeoServerͨ¹ýÌṩһ¸ö»ùÓڳ߶ȵĽӿڣ¬Ê¹Óû§¿ÉÄÜ·½±ãµØ½Ó¼ûºÍÖÎÀíµØÍ¼Êý¾Ý£¬¿í·ºÀûÓÃÓÚµØÀíÐÅϢϵͳ¡¢µØÍ¼·þÎñºÍ¿Õ¼äÊý¾ÝµÄ¹²ÏíÓë·ÖÎö¡£
2025Äê11ÔÂ26ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½GeoServer´æÔÚXML±í²¿ÊµÌå×¢Èë·ì϶£¬¸Ã·ì϶ԴÓÚÀûÓ÷¨Ê½Í¨¹ýÌØ¶¨µÄ/geoserver/wms½Ó¿Ú½Ó¹ÜXMLÊäÈ룬µ«Î´¶ÔÊäÈë½øÐгä·ÖµÄËãÕÊ»òÏÞ¶È£¬ÔÊÐí¹¥»÷ÕßÔÚXMLÒªÇóÖнç˵±í²¿ÊµÌå¡£XML±í²¿ÊµÌå¹¥»÷ÊÇÖ¸µ±Ô̺¬¶Ô±í²¿ÊµÌåÒýÓõÄXMLÊäÈë±»ÅäÖò»µ±µÄXML½âÎöÆ÷´¦ÖÃʱ£¬¿ÉÄÜÒý·¢µÄ¹¥»÷¡£ÕâÀ๥»÷¿ÉÄܵ¼Ö»úÃÜÊý¾Ýй¶¡¢·þÎñ»Ø¾ø£¨DoS£©¡¢¶Ë¿ÚɨÃèµÈÑϳÁ°²È«ÎÊÌâ¡£¹¥»÷Õßͨ¹ýÀûÓø÷ì϶£¬Äܹ»½Ó¼û·þÎñÆ÷ÎļþϵͳÖеÄËÁÒâÎļþ£¬½øÐзþÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©£¬ÓëÄÚ²¿ÏµÍ³½»»¥£¬ÉõÖÁÌáÒé×ÊÔ´ºÄ¾¡Ð͵ÄDoS¹¥»÷£¬´Ó¶øÔì³Éϵͳ²»³ÉÓá£
¶þ¡¢Ó°ÏìÁìÓò
2.26.0 <= docker.osgeo.org/geoserver <= 2.26.1docker.osgeo.org/geoserver <= 2.25.52.26.0 <= org.geoserver.web:gs-web-app <= 2.26.1org.geoserver.web:gs-web-app <= 2.25.52.26.0 <= org.geoserver:gs-wms <= 2.26.1org.geoserver:gs-wms <= 2.25.5
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
¹Ù·½ÒѰ䲼½¨¸´²¹¶¡£¬ÒÔ½¨¸´¸Ã·ì϶¡£
docker.osgeo.org/geoserver >= 2.26.2docker.osgeo.org/geoserver >= 2.25.6org.geoserver.web:gs-web-app >= 2.26.2org.geoserver.web:gs-web-app >= 2.25.6org.geoserver:gs-wms >= 2.26.2org.geoserver:gs-wms >= 2.25.6
ÏÂÔØÁ´½Ó£ºhttps://github.com/geoserver/geoserver/releases/
3.2 һʱ´ëÊ©
3.3 ͨÓý¨Òé
? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£? ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£? ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£? ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£? ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://github.com/geoserver/geoserver/security/advisories/GHSA-fjf5-xgmq-5525/https://nvd.nist.gov/vuln/detail/CVE-2025-58360