CVE-2024-34711: GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)

Published Jun 10, 2025
·
Updated

Summary An improper URI validation vulnerability exists that enables an unauthorized attacker to perform XML External Entities (XEE) attack, then send GET request to any HTTP server. Attacker can abuse this to scan internal networks and gain information about them then exploit further. Moreover, attacker can read limited .xsd file on system.

Details By default, GeoServer use PreventLocalEntityResolver class from GeoTools to filter out malicious URIs in XML entities before resolving them. The URI must match the regex (?i)(jar:file|http|vfs)[^?#;]\\.xsd. But the regex leaves a chance for attackers to request to any HTTP server or limited file.

Impact

An unauthenticated attacker can: 1. Scan internal network to gain insight about it and exploit further. 2. SSRF to endpoint ends with .xsd. 3. Read limited .xsd file on system.

Mitigation

1. Define the system property ENTITYRESOLUTIONALLOWLIST to limit the supported external schema locaitons. 2. The built-in allow list covers the locations required for the operation of OGC web services: www.w3.org,schemas.opengis.net,www.opengis.net,inspire.ec.europa.eu/schemas. 3. The user guide provides details on how to add additional locations (this is required for app-schema plugin where a schema is supplied to define an output format).

Resolution

1. GeoServer 2.25.0 and greater default to the use of ENTITYRESOLUTIONALLOWLIST and does not require you to provide a system property. 2. The use of ENTITYRESOLUTIONALLOWLIST is still supported if you require additional schema locations to be supported beyond the built-in allow list. 3. GeoServer 2.25.1 change ENTITYRESOLUTIONALLOWLIST no longer supports regular expressions

References

External Entities Resolution (GeoServer User Guide)

Credits Le Mau Anh Phong from VNG Security Response Center & VNUHCM - University of Information Technology

Other sources

GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables an unauthorized attacker to perform XML External Entities (XEE) attack, then send GET request to any HTTP server. By default, GeoServer use PreventLocalEntityResolver class from GeoTools to filter out malicious URIs in XML entities before resolving them. The URI must match the regex (?i)(jar:file|http|vfs)[^?#;]\\.xsd. But the regex leaves a chance for attackers to request to any HTTP server or limited file. Attacker can abuse this to scan internal networks and gain information about them then exploit further. GeoServer 2.25.0 and greater default to the use of ENTITYRESOLUTIONALLOWLIST and does not require you to provide a system property.

MITRE

Affected Software

3 affected componentsFixes available
maven/org.geoserver.main:gs-main<2.25.0
2.25.0
maven/org.geoserver.web:gs-web-app<2.25.0
2.25.0
OSGeo GeoServer<2.25.0

Event History

Jun 10, 2025
Advisory Published
via GitHub·02:13 PM
Data Sourced
via GitHub·02:13 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
Affected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-34711?

CVE-2024-34711 is a vulnerability with a moderate severity rating due to its potential for unauthorized access through XML External Entities attacks.

2

How do I fix CVE-2024-34711?

To fix CVE-2024-34711, upgrade to version 2.25.0 of the affected packages org.geoserver.main:gs-main and org.geoserver.web:gs-web-app.

3

What types of attacks can be performed due to CVE-2024-34711?

CVE-2024-34711 allows attackers to conduct XML External Entities (XEE) attacks, enabling them to send unauthorized GET requests to any HTTP server.

4

Which software versions are affected by CVE-2024-34711?

CVE-2024-34711 affects versions prior to 2.25.0 of the org.geoserver.main:gs-main and org.geoserver.web:gs-web-app packages.

5

What impact does CVE-2024-34711 have on internal networks?

CVE-2024-34711 can potentially allow unauthorized attackers to scan and gather information about internal networks, leading to further exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203