CVE-2025-52465: GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
A vulnerability exists that allows an authenticated administrator with access to GeoServer’s security system to pass arbitrary file names to the Master Password Dump web page and create files containing the master password in plaintext. The provided file name must be an absolute path to the target file, the target file can not already exist and all parent directories must already exist.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-52465 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →