S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-25157 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in Geoserver affects v. before 2.21.4.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-25157
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service (WMS) protocols. CQL is also supported through the Web Coverage Service (WCS) protocol for ImageMosaic coverages. Users are advised to upgrade to either version 2.21.4, or version 2.22.2 to resolve this issue. Users unable to upgrade should disable the PostGIS Datastore *encode functions* setting to mitigate ``strEndsWith``, ``strStartsWith`` and ``PropertyIsLike `` misuse and enable the PostGIS DataStore *preparedStatements* setting to mitigate the ``FeatureId`` misuse.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
geoserverby geoserver
>= 2.22.0, < 2.22.2
Updated Aug 19, 2026View on NVD →
Detail

eoServer is an open-source server software designed in Java, allowing its users to edit and share geospatial data. It provides support for the OGC Filter expression language and Common Query Language (CQL) through its Web Feature Service (WFS) and Web Map Service (WMS) protocols. With GeoServer's support for CQL, it is also possible to get the benefit from its Web Coverage Service (WCS) protocol for ImageMosaic coverages. The software is designed to provide developers with a user-friendly platform through which they can manipulate geospatial data and make it available for others to access and edit.

CVE-2023-25157 is a vulnerability detected in GeoServer, making the software exposed to security risks. This particular vulnerability exposes the CQL functions' misuses such as `strEndsWith`, `strStartsWith`, and `PropertyIsLike` when executed in the PostGIS Datastore. Additionally, the `FeatureId` misuse further exposes the software to possible exploitation. Given the severity of this vulnerability, the developers of GeoServer suggest that users upgrade to either version 2.21.4 or version 2.22.2.

Exploiting this vulnerability can lead to unauthorized access to confidential data stored in GeoServer. It also opens the possibility of Denial of Service (DoS) attacks, which could cripple the server's performance and affect the users' ability to access the geospatial data stores. With no patches to remediate the vulnerability, exposing sensitive data or availability disruption is a severe security risk with this vulnerability.

GeoServer is an excellent open-source platform for developers to manage, share and edit geospatial data with ease. However, vulnerabilities like CVE-2023-25157 pose significant security risks and require immediate attention. By utilizing the security features of professional computing platforms like s4e.io, even amateurs or unexperienced users can identify cybersecurity threats and keep their servers protected against possible incidents. With the increasing need to secure digital assets more than ever, employing professional security platforms is no longer an option, but a must.

 

REFERENCES

Solution Advice

Those utilizing GeoServer can take the following precautions to protect their software against CVE-2023-25157:

  • Upgrade to GeoServer V2.21.4 or V2.22.2.
  • Disable the PostGIS Datastore encode functions setting to mitigate `strEndsWith`, `strStartsWith`, and `PropertyIsLike` misuses.
  • Enable the PostGIS DataStore prepared statements setting to mitigate the `FeatureId` misuse.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.