¡¾·ì϶¹«¸æ¡¿GeoServer XML±í²¿ÊµÌå×¢Èë·ì϶(CVE-2025-58360)

°ä²¼¹¦·ò 2025-11-26

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

GeoServer XML±í²¿ÊµÌå×¢Èë·ì϶

CVE   ID

CVE-2025-58360

·ì϶ÀàÐÍ

XXE ×¢Èë

·¢ÏÖ¹¦·ò

2025-11-26

·ì϶ÆÀ·Ö

8.2

·ì϶µÈ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


GeoServerÊÇÒ»¸ö¿ªÔ´µÄµØÀíÐÅϢϵͳ£¨GIS£©·þÎñÆ÷£¬ÖØÒªÓÃÓÚ°ä²¼¡¢¹²ÏíºÍ±à×ëµØÀí¿Õ¼äÊý¾Ý¡£ËüÖ§³Ö¶àÖֳ߶ȵÄÊ¢¿ªµØÀíÊý¾ÝÌåʽ£¬Ô̺¬WMS£¨Web Map Service£©¡¢WFS£¨Web Feature Service£©ºÍWCS£¨Web Coverage Service£©£¬¿ÉÄÜÓë¸÷ÀàGIS¿Í»§¶Ë½øÐн»»¥¡£GeoServerͨ¹ýÌṩһ¸ö»ùÓڳ߶ȵĽӿÚ£¬Ê¹Óû§¿ÉÄÜ·½±ãµØ½Ó¼ûºÍÖÎÀíµØÍ¼Êý¾Ý£¬¿í·ºÀûÓÃÓÚµØÀíÐÅϢϵͳ¡¢µØÍ¼·þÎñºÍ¿Õ¼äÊý¾ÝµÄ¹²ÏíÓë·ÖÎö¡£


2025Äê11ÔÂ26ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½GeoServer´æÔÚXML±í²¿ÊµÌå×¢Èë·ì϶£¬¸Ã·ì϶ԴÓÚÀûÓ÷¨Ê½Í¨¹ýÌØ¶¨µÄ/geoserver/wms½Ó¿Ú½Ó¹ÜXMLÊäÈ룬µ«Î´¶ÔÊäÈë½øÐгä·ÖµÄËãÕÊ»òÏÞ¶È£¬ÔÊÐí¹¥»÷ÕßÔÚXMLÒªÇóÖнç˵±í²¿ÊµÌå¡£XML±í²¿ÊµÌå¹¥»÷ÊÇÖ¸µ±Ô̺¬¶Ô±í²¿ÊµÌåÒýÓõÄXMLÊäÈë±»ÅäÖò»µ±µÄXML½âÎöÆ÷´¦ÖÃʱ£¬¿ÉÄÜÒý·¢µÄ¹¥»÷¡£ÕâÀ๥»÷¿ÉÄܵ¼Ö»úÃÜÊý¾Ýй¶¡¢·þÎñ»Ø¾ø£¨DoS£©¡¢¶Ë¿ÚɨÃèµÈÑϳÁ°²È«ÎÊÌâ¡£¹¥»÷Õßͨ¹ýÀûÓø÷ì϶£¬Äܹ»½Ó¼û·þÎñÆ÷ÎļþϵͳÖеÄËÁÒâÎļþ£¬½øÐзþÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©£¬ÓëÄÚ²¿ÏµÍ³½»»¥£¬ÉõÖÁÌáÒé×ÊÔ´ºÄ¾¡Ð͵ÄDoS¹¥»÷£¬´Ó¶øÔì³Éϵͳ²»³ÉÓá£


¶þ¡¢Ó°ÏìÁìÓò


2.26.0 <= docker.osgeo.org/geoserver <= 2.26.1
docker.osgeo.org/geoserver <= 2.25.5
2.26.0 <= org.geoserver.web:gs-web-app <= 2.26.1
org.geoserver.web:gs-web-app <= 2.25.5
2.26.0 <= org.geoserver:gs-wms <= 2.26.1
org.geoserver:gs-wms <= 2.25.5


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


¹Ù·½ÒѰ䲼½¨¸´²¹¶¡£¬ÒÔ½¨¸´¸Ã·ì϶¡£

docker.osgeo.org/geoserver >= 2.26.2
docker.osgeo.org/geoserver >= 2.25.6
org.geoserver.web:gs-web-app >= 2.26.2
org.geoserver.web:gs-web-app >= 2.25.6
org.geoserver:gs-wms >= 2.26.2
org.geoserver:gs-wms >= 2.25.6


ÏÂÔØÁ´½Ó£ºhttps://github.com/geoserver/geoserver/releases/


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://github.com/geoserver/geoserver/security/advisories/GHSA-fjf5-xgmq-5525/
https://nvd.nist.gov/vuln/detail/CVE-2025-58360