Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.geoserver.web/gs-web-app
  4. ›
  5. CVE-2025-52465

CVE-2025-52465: GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page

June 12, 2026

A vulnerability exists that allows an authenticated administrator with access to GeoServer’s security system to pass arbitrary file names to the Master Password Dump web page and create files containing the master password in plaintext. The provided file name must be an absolute path to the target file, the target file can not already exist and all parent directories must already exist.

References

  • github.com/advisories/GHSA-7qmg-grcp-qf25
  • github.com/geoserver/geoserver/pull/8584
  • github.com/geoserver/geoserver/security/advisories/GHSA-7qmg-grcp-qf25
  • nvd.nist.gov/vuln/detail/CVE-2025-52465

Code Behaviors & Features

Detect and mitigate CVE-2025-52465 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.26.4, all versions starting from 2.27.0 before 2.27.3

Fixed versions

  • 2.26.4
  • 2.27.3

Solution

Upgrade to versions 2.26.4, 2.27.3 or above.

Impact 7.2 HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-73: External Control of File Name or Path

Source file

maven/org.geoserver.web/gs-web-app/CVE-2025-52465.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:22:10 +0000.