OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability
GeoServer는 사용자가 지리 공간 데이터를 공유하고 편집할 수 있게 하는 오픈 소스 서버입니다. version 2.26.0부터 2.26.2 이전까지 및 2.25.6 이전에서 XML External Entity(XXE) 취약점이 확인되었습니다. 애플리케이션은 특정 엔드포인트 /geoserver/wms의 GetMap 작업을 통해 XML 입력을 받습니다. 그러나 이 입력이 충분히 정제되거나 제한되지 않아 공격자가 XML 요청 내에 외부 엔터티를 정의할 수 있습니다. 이 문제는 GeoServer 2.25.6, GeoServer 2.26.3 및 GeoServer 2.27.0에서 패치되었습니다.
GeoServer는 사용자가 지리 공간 데이터를 공유하고 편집할 수 있게 하는 오픈 소스 서버입니다. version 2.26.0부터 2.26.2 이전까지 및 2.25.6 이전에서 XML External Entity(XXE) 취약점이 확인되었습니다. 애플리케이션은 특정 엔드포인트 /geoserver/wms의 GetMap 작업을 통해 XML 입력을 받습니다. 그러나 이 입력이 충분히 정제되거나 제한되지 않아 공격자가 XML 요청 내에 외부 엔터티를 정의할 수 있습니다. 이 문제는 GeoServer 2.25.6, GeoServer 2.26.3 및 GeoServer 2.27.0에서 패치되었습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input is not sufficiently sanitized or restricted, allowing an attacker to define external entities within the XML request. This issue has been patched in GeoServer 2.25.6, GeoServer 2.26.3, and GeoServer 2.27.0.
영향 제품·버전
제품 OSGeo GeoServer
영향 버전 OSGeo GeoServer < 2.25.6, >= 2.26.0 < 2.26.2
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
조치 기한: 2026.01.01
해당사항 확인방법
OSGeo GeoServer의 현재 전체 버전이 공식 영향 범위(OSGeo GeoServer < 2.25.6, >= 2.26.0 < 2.26.2)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 OSGeo GeoServer 2.25.6, 2.26.2 기준을 충족하는지 확인합니다. 이어서 XML 외부 개체(XXE) 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.
필드별 과거 원문을 추정하지 않습니다. 각 시점의 현재 값과 공식 출처를 대조해 변경 여부를 확인하세요.
기술 정보
CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE CWE-611
KEV 등록일 2025.12.11
랜섬웨어 캠페인 사용 미확인
CISA 비고 This vulnerability affects an open-source component, third-party library, or a protocol used by different products. For more information, please see: https://github.com/geoserver/geoserver/security/advisories/GHSA-fjf5-xgmq-5525 ; https://osgeo-org.atlassian.net/browse/GEOS-11922 ; https://nvd.nist.gov/vuln/detail/CVE-2025-58360