GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.23.4 and 2.24.1 that enables an authenticated administrator with workspace-level privileges to store a JavaScript payload in the GeoServer catalog that will execute in the context of another user's browser when viewed in the MapML HTML Page. The MapML extension must be installed and access to the MapML HTML Page is available to all users although data security may limit users' ability to trigger the XSS. Versions 2.23.4 and 2.24.1 contain a patch for this issue.
{
"cwe_ids": [
"CWE-79"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23819.json"
}{
"cpe": [
"cpe:2.3:a:geoserver:geoserver:*:*:*:*:*:*:*:*",
"cpe:2.3:a:geoserver:geoserver:2.24.0:-:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.23.4"
},
{
"introduced": "2.24.0-NA"
},
{
"last_affected": "2.24.0-NA"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING",
"REFERENCES"
]
}"2026-07-22T02:51:00Z"
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 3777.0,
"function_hash": "239680004279125162851931711572080742131"
},
"signature_version": "v1",
"source": "https://github.com/geoserver/geoserver/commit/df65ff05250cbb498c78af906d66e0c084ace8a1",
"id": "CVE-2024-23819-4a8a1259",
"target": {
"function": "Html",
"file": "src/extension/mapml/src/main/java/org/geoserver/mapml/MapMLController.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"65077943500788815397264523213804244676",
"218604989177063196176043364561250972233",
"146590680116546800993618648263277227550",
"123715224335185056784904651546892365426",
"186185190422556489988393485004673206871",
"283763982223064379983318795302235056034",
"178245634390026907093385612144396736708",
"219600184048974634611793322713385977935",
"134417855305653130415318914527344571869",
"50746832850229364887597583974676925481",
"271886748005309143987815747979496659463",
"129199300497202181269202053219863680832",
"7333166887280497327199556357809729958",
"148411633797465219350235258889859467273",
"300585378552581359563288533472626991497",
"57141928664799315693871461367450528423",
"38467330505945939184088880981392368809",
"261289796439750320334430936808098243179",
"142688571752303247072083142039695678116",
"86458305267955801731200172932651151729",
"171925648297419537779397650147707706789",
"112218752145751437354101751503957456522",
"90064130081335305534846657363823846628",
"145263942830732521388711565445083955154",
"302110011637524245045355569756376234474"
]
},
"signature_version": "v1",
"source": "https://github.com/geoserver/geoserver/commit/df65ff05250cbb498c78af906d66e0c084ace8a1",
"id": "CVE-2024-23819-53af45d9",
"target": {
"file": "src/extension/mapml/src/main/java/org/geoserver/mapml/MapMLController.java"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 3777.0,
"function_hash": "239680004279125162851931711572080742131"
},
"signature_version": "v1",
"source": "https://github.com/geoserver/geoserver/commit/6f04adbdc6c289f5cb815b1462a6bd790e3fb6ef",
"id": "CVE-2024-23819-621d46f2",
"target": {
"function": "Html",
"file": "src/extension/mapml/src/main/java/org/geoserver/mapml/MapMLController.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"4433584476051629983312554954222778168",
"337322681642976655406424142986340444660",
"125353184608319289991298161174815138718",
"222209710117566810348643750145785052403",
"318807950298328194102144584562818676885",
"268291692218397166850296576979021993711"
]
},
"signature_version": "v1",
"source": "https://github.com/geoserver/geoserver/commit/6f04adbdc6c289f5cb815b1462a6bd790e3fb6ef",
"id": "CVE-2024-23819-c201adf4",
"target": {
"file": "src/extension/mapml/src/test/java/org/geoserver/mapml/MapMLControllerTest.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"65077943500788815397264523213804244676",
"218604989177063196176043364561250972233",
"146590680116546800993618648263277227550",
"123715224335185056784904651546892365426",
"186185190422556489988393485004673206871",
"283763982223064379983318795302235056034",
"178245634390026907093385612144396736708",
"219600184048974634611793322713385977935",
"134417855305653130415318914527344571869",
"50746832850229364887597583974676925481",
"271886748005309143987815747979496659463",
"129199300497202181269202053219863680832",
"7333166887280497327199556357809729958",
"148411633797465219350235258889859467273",
"300585378552581359563288533472626991497",
"57141928664799315693871461367450528423",
"38467330505945939184088880981392368809",
"261289796439750320334430936808098243179",
"142688571752303247072083142039695678116",
"86458305267955801731200172932651151729",
"171925648297419537779397650147707706789",
"112218752145751437354101751503957456522",
"90064130081335305534846657363823846628",
"145263942830732521388711565445083955154",
"302110011637524245045355569756376234474"
]
},
"signature_version": "v1",
"source": "https://github.com/geoserver/geoserver/commit/6f04adbdc6c289f5cb815b1462a6bd790e3fb6ef",
"id": "CVE-2024-23819-cb81259d",
"target": {
"file": "src/extension/mapml/src/main/java/org/geoserver/mapml/MapMLController.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"4433584476051629983312554954222778168",
"337322681642976655406424142986340444660",
"125353184608319289991298161174815138718",
"222209710117566810348643750145785052403",
"318807950298328194102144584562818676885",
"49968843778871709673695640287210291466"
]
},
"signature_version": "v1",
"source": "https://github.com/geoserver/geoserver/commit/df65ff05250cbb498c78af906d66e0c084ace8a1",
"id": "CVE-2024-23819-d852dde3",
"target": {
"file": "src/extension/mapml/src/test/java/org/geoserver/mapml/MapMLControllerTest.java"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-23819.json"