Sploitus

CVE-2024-34711

No indexed exploits for CVE-2024-34711 yet

GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables an unauthorized attacker to perform XML External Entities (XEE) attack, then send GET request to any HTTP server. By default, GeoServer use PreventLocalEntityResolver class from GeoTools to filter out malicious URIs in XML entities before resolving them. The URI must match the regex (?i)(jar:file|http|vfs)[^?#;]*\\.xsd. But the regex leaves a chance for attackers to request to any HTTP server or limited file. Attacker can abuse this to scan internal networks and gain information about them then exploit further. GeoServer 2.25.0 and greater default to the use of ENTITY_RESOLUTION_ALLOWLIST and does not require you to provide a system property.

Affected products
Geoserver
Osgeo Geoserver
< 2.25.0
Fix
Available
CVSS 3.1
9.3 CRITICAL
EPSS
0.3% (18th percentile)
Weakness
CWE-611, CWE-200, CWE-918
NVD status
Analyzed
Published
2025-06-10
CVE-2024-34711 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-34711 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-34711 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.