Skip to content

Commit 8fbd16e

Browse files
authored
CVE disclosure and release anouncements inconsistent (#237)
We now use placeholder CVEs to avoid this kind of inconsistency
1 parent 9c143aa commit 8fbd16e

5 files changed

+7
-3
lines changed

_posts/2024-02-18-geoserver-2-23-5-released.md

+3-1
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ with downloads
2424
This is the last planned maintenance release of GeoServer 2.23.x, providing existing installations with minor updates and bug fixes.
2525
Sites using the 2.23.x series are encouraged to upgrade to GeoServer 2.24.x, or eventually wait next month, for the 2.25.0 release, and upgrade their installation, with the help of the [upgrade guide](https://docs.geoserver.org/main/en/user/installation/upgrade.html#notes-on-upgrading-specific-versions).
2626

27-
GeoServer 2.23.5 is made in conjunction with GeoTools 29.5, and GeoWebCache 1.23.4.
27+
GeoServer 2.23.5 is made in conjunction with GeoTools 29.5, and GeoWebCache 1.23.4.
2828

2929
Thanks to Andrea Aime (GeoSolutions) for making this release.
3030

@@ -34,6 +34,8 @@ This release addresses security vulnerabilities and is considered an essential u
3434

3535
- [CVE-2024-23634](https://github.com/geoserver/geoserver/security/advisories/GHSA-75m5-hh4r-q9gx) Arbitrary file renaming vulnerability in REST Coverage/Data Store API (Moderate)
3636

37+
* [CVE-2024-24749](https://github.com/geoserver/geoserver/security/advisories/GHSA-jhqx-5v5g-mpf3) Classpath resource disclosure in GWC Web Resource API on Windows / Tomcat (Moderate)
38+
3739
See project [security policy](https://github.com/geoserver/geoserver/blob/main/SECURITY.md) for more information on how security vulnerabilities are managed.
3840

3941
## Release notes

_posts/2024-04-18-geoserver-2-24-3-released.md

+2
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,8 @@ Thanks to Andrea Aime (GeoSolutions) for making this release.
3333

3434
[geoserver-2.24.3-patches.zip](https://sourceforge.net/projects/geoserver/files/GeoServer/2.24.3/geoserver-2.24.3-patches.zip/download) (replacing `gt-app-schema`, `gt-complex` and `gt-xsd-core` jars) has been provided by Andrea (GeoSolutions)
3535

36+
* [CVE-2024-24749](https://github.com/geoserver/geoserver/security/advisories/GHSA-jhqx-5v5g-mpf3) Classpath resource disclosure in GWC Web Resource API on Windows / Tomcat (Moderate)
37+
3638
See project [security policy](https://github.com/geoserver/geoserver/blob/main/SECURITY.md) for more information on how security vulnerabilities are managed.
3739

3840

_posts/2024-05-23-geoserver-2-25-1-released.md

+2
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,8 @@ This release addresses security vulnerabilities and is considered an essential u
3737

3838
[geoserver-2.25.1-patches.zip](https://sourceforge.net/projects/geoserver/files/GeoServer/2.25.1/geoserver-2.25.1-patches.zip/download) (replacing `gt-app-schema`, `gt-complex` and `gt-xsd-core` jars) has been provided by Andrea (GeoSolutions)
3939

40+
* [CVE-2024-34696](https://github.com/geoserver/geoserver/security/advisories/GHSA-j59v-vgcr-hxvf) GeoServer About Status lists sensitive Environmental Variables (Moderate)
41+
4042
See project [security policy](https://github.com/geoserver/geoserver/blob/main/SECURITY.md) for more information on how security vulnerabilities are managed.
4143

4244
## Raster Attribute Table Extension

_posts/2024-06-18-geoserver-2-24-4-released.md

-1
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,6 @@ Thanks to Peter Smythe (AfriGIS) for making this release.
3232
This release addresses security vulnerabilities and is considered an essential upgrade for production systems.
3333

3434
* [CVE-2024-36401](https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv) Remote Code Execution (RCE) vulnerability in evaluating property name expressions (Critical)
35-
* [CVE-2024-24749](https://github.com/geoserver/geoserver/security/advisories/GHSA-jhqx-5v5g-mpf3) Classpath resource disclosure in GWC Web Resource API on Windows / Tomcat (Moderate)
3635
* [CVE-2024-34696](https://github.com/geoserver/geoserver/security/advisories/GHSA-j59v-vgcr-hxvf) GeoServer About Status lists sensitive Environmental Variables (Moderate)
3736

3837
The use of the CVE system allows the GeoServer team to reach a wider audience than blog posts. See project [security policy](https://github.com/geoserver/geoserver/blob/main/SECURITY.md) for more information on how security vulnerabilities are managed.

_posts/2024-06-18-geoserver-2-25-2-released.md

-1
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,6 @@ This release addresses security vulnerabilities and is considered an essential u
3232

3333
* [CVE-2024-36401](https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv) Remote Code Execution (RCE) vulnerability in evaluating property name expressions (Critical)
3434
* [CVE-2024-24749](https://github.com/geoserver/geoserver/security/advisories/GHSA-jhqx-5v5g-mpf3) Classpath resource disclosure in GWC Web Resource API on Windows / Tomcat (Moderate)
35-
* [CVE-2024-34696](https://github.com/geoserver/geoserver/security/advisories/GHSA-j59v-vgcr-hxvf) GeoServer About Status lists sensitive Environmental Variables (Moderate)
3635
* CVE-2024-35230 Moderate
3736

3837
The use of the CVE system allows the GeoServer team to reach a wider audience than blog posts. See the project [security policy](https://github.com/geoserver/geoserver/blob/main/SECURITY.md) for more information on how security vulnerabilities are managed.

0 commit comments

Comments
 (0)