Skip to content

Commit

Permalink
Sync CVE disclosure and release anouncements
Browse files Browse the repository at this point in the history
  • Loading branch information
jodygarnett committed Jan 7, 2025
1 parent 15ff38f commit 39bc707
Showing 1 changed file with 0 additions and 1 deletion.
1 change: 0 additions & 1 deletion _posts/2024-06-13-geoserver-2-23-6-released.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,6 @@ Thanks to Jody Garnett (GeoCat) for making this release on behalf of GeoCat cust
This release addresses security vulnerabilities and is considered an essential update for production systems.

* [CVE-2024-36401](https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv) Remote Code Execution (RCE) vulnerability in evaluating property name expressions (Critical)
* [CVE-2024-24749](https://github.com/geoserver/geoserver/security/advisories/GHSA-jhqx-5v5g-mpf3) Classpath resource disclosure in GWC Web Resource API on Windows / Tomcat (Moderate)

See project [security policy](https://github.com/geoserver/geoserver/blob/main/SECURITY.md) for more information on how security vulnerabilities are managed.

Expand Down

0 comments on commit 39bc707

Please sign in to comment.