CVE-2023-51445
Java vulnerability analysis and mitigation

Overview

GeoServer, an open source software server written in Java for sharing and editing geospatial data, contains a stored cross-site scripting (XSS) vulnerability (CVE-2023-51445) in versions prior to 2.23.3 and 2.24.0. The vulnerability enables an authenticated administrator with workspace-level privileges to store a JavaScript payload in uploaded style/legend resources that can execute in another administrator's browser when viewed in the REST Resources API (GitHub Advisory).

Technical details

The vulnerability allows an attacker to upload malicious files either through the New Style page or directly via PUT requests to the REST API. When these files are later viewed through the REST Resources API, the malicious JavaScript executes in the context of the viewing administrator's browser. The vulnerability has been assigned a CVSS v3.1 base score of 4.8 (Medium) with vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N (GitHub Advisory).

Impact

If successfully exploited, an attacker can perform any actions within the application that the victim user can perform, view and modify information accessible to the victim user, and initiate interactions with other application users that appear to originate from the victim. The vulnerability is particularly concerning as it could be used to steal user cookies since they don't use HTTPOnly flag (GitHub Advisory).

Exploitability

The vulnerability requires an authenticated administrator with workspace-level privileges to exploit. The attacker must first upload a malicious file containing JavaScript payload through either the New Style page or via PUT requests to the REST API. The payload executes when another administrator views the file through the REST Resources API. Access to the REST Resources API is limited to full administrators by default (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in versions 2.23.3 and 2.24.0. Organizations should upgrade to these or newer versions. Additionally, administrators should carefully consider granting non-administrators access to the REST Resources API endpoint as it may allow access to files containing sensitive information (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-63219HIGH8.6
  • Java logoJava
  • org.geonetwork-opensource:gn-services
NoYesSep 03, 2026
CVE-2026-49464HIGH8.1
  • Java logoJava
  • nl.nl-portal:taak
NoYesSep 11, 2026
CVE-2026-55864HIGH7.7
  • Java logoJava
  • org.geonetwork-opensource:gn-web-app
NoYesSep 09, 2026
CVE-2026-49463MEDIUM6.5
  • Java logoJava
  • nl.nl-portal:besluiten
NoYesSep 11, 2026
CVE-2026-49439MEDIUM4.3
  • Java logoJava
  • io.openremote:openremote-manager
NoYesSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management