¡¾·ì϶¹«¸æ¡¿GeoServer XML±í²¿ÊµÌå×¢Èë·ì϶(CVE-2025-58360)

°ä²¼¹¦·ò 2025-11-26

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

GeoServer XML±í²¿ÊµÌå×¢Èë·ì϶

CVE   ID

CVE-2025-58360

·ì϶ÀàÐÍ

XXE ×¢Èë

·¢ÏÖ¹¦·ò

2025-11-26

·ì϶ÆÀ·Ö

8.2

·ì϶µÈ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


GeoServerÊÇÒ»¸ö¿ªÔ´µÄµØÀíÐÅϢϵͳ£¨GIS£©·þÎñÆ÷£¬£¬£¬£¬£¬ÖØÒªÓÃÓÚ°ä²¼¡¢¹²ÏíºÍ±à×ëµØÀí¿Õ¼äÊý¾Ý¡£¡£¡£¡£¡£¡£ËüÖ§³Ö¶àÖֳ߶ȵÄÊ¢¿ªµØÀíÊý¾ÝÌåʽ£¬£¬£¬£¬£¬Ô̺¬WMS£¨Web Map Service£©¡¢WFS£¨Web Feature Service£©ºÍWCS£¨Web Coverage Service£©£¬£¬£¬£¬£¬¿ÉÄÜÓë¸÷ÀàGIS¿Í»§¶Ë½øÐн»»¥¡£¡£¡£¡£¡£¡£GeoServerͨ¹ýÌṩһ¸ö»ùÓڳ߶ȵĽӿÚ£¬£¬£¬£¬£¬Ê¹Óû§¿ÉÄÜ·½±ãµØ½Ó¼ûºÍÖÎÀíµØÍ¼Êý¾Ý£¬£¬£¬£¬£¬¿í·ºÀûÓÃÓÚµØÀíÐÅϢϵͳ¡¢µØÍ¼·þÎñºÍ¿Õ¼äÊý¾ÝµÄ¹²ÏíÓë·ÖÎö¡£¡£¡£¡£¡£¡£


2025Äê11ÔÂ26ÈÕ£¬£¬£¬£¬£¬8827Ì«Ñô¼¯Íż¯ÍÅVSRC¼à²âµ½GeoServer´æÔÚXML±í²¿ÊµÌå×¢Èë·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓÚÀûÓ÷¨Ê½Í¨¹ýÌØ¶¨µÄ/geoserver/wms½Ó¿Ú½Ó¹ÜXMLÊäÈ룬£¬£¬£¬£¬µ«Î´¶ÔÊäÈë½øÐгä·ÖµÄËãÕÊ»òÏÞ¶È£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÔÚXMLÒªÇóÖнç˵±í²¿ÊµÌå¡£¡£¡£¡£¡£¡£XML±í²¿ÊµÌå¹¥»÷ÊÇÖ¸µ±Ô̺¬¶Ô±í²¿ÊµÌåÒýÓõÄXMLÊäÈë±»ÅäÖò»µ±µÄXML½âÎöÆ÷´¦ÖÃʱ£¬£¬£¬£¬£¬¿ÉÄÜÒý·¢µÄ¹¥»÷¡£¡£¡£¡£¡£¡£ÕâÀ๥»÷¿ÉÄܵ¼Ö»úÃÜÊý¾Ýй¶¡¢·þÎñ»Ø¾ø£¨DoS£©¡¢¶Ë¿ÚɨÃèµÈÑϳÁ°²È«ÎÊÌâ¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÀûÓø÷ì϶£¬£¬£¬£¬£¬Äܹ»½Ó¼û·þÎñÆ÷ÎļþϵͳÖеÄËÁÒâÎļþ£¬£¬£¬£¬£¬½øÐзþÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©£¬£¬£¬£¬£¬ÓëÄÚ²¿ÏµÍ³½»»¥£¬£¬£¬£¬£¬ÉõÖÁÌáÒé×ÊÔ´ºÄ¾¡Ð͵ÄDoS¹¥»÷£¬£¬£¬£¬£¬´Ó¶øÔì³Éϵͳ²»³ÉÓᣡ£¡£¡£¡£¡£


¶þ¡¢Ó°ÏìÁìÓò


2.26.0 <= docker.osgeo.org/geoserver <= 2.26.1
docker.osgeo.org/geoserver <= 2.25.5
2.26.0 <= org.geoserver.web:gs-web-app <= 2.26.1
org.geoserver.web:gs-web-app <= 2.25.5
2.26.0 <= org.geoserver:gs-wms <= 2.26.1
org.geoserver:gs-wms <= 2.25.5


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


¹Ù·½ÒѰ䲼½¨¸´²¹¶¡£¬£¬£¬£¬£¬ÒÔ½¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£¡£

docker.osgeo.org/geoserver >= 2.26.2
docker.osgeo.org/geoserver >= 2.25.6
org.geoserver.web:gs-web-app >= 2.26.2
org.geoserver.web:gs-web-app >= 2.25.6
org.geoserver:gs-wms >= 2.26.2
org.geoserver:gs-wms >= 2.25.6


ÏÂÔØÁ´½Ó£ºhttps://github.com/geoserver/geoserver/releases/


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬£¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£¡£¡£¡£¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬£¬£¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬£¬£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£¡£¡£¡£¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://github.com/geoserver/geoserver/security/advisories/GHSA-fjf5-xgmq-5525/
https://nvd.nist.gov/vuln/detail/CVE-2025-58360