Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17684 | GeoServer Infinite Loop Vulnerability in Jiffle process |
Github GHSA |
GHSA-gr67-pwcv-76gf | GeoServer Infinite Loop Vulnerability in Jiffle process |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 27 Aug 2025 01:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Osgeo
Osgeo geoserver |
|
| CPEs | cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Osgeo
Osgeo geoserver |
Sat, 12 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 11 Jun 2025 01:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Jun 2025 00:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be executed by GeoServer, either as a rendering transformation in WMS dynamic styles or as a WPS process, that can enter an infinite loop to trigger denial of service. This vulnerability is fixed in 2.27.0, 2.26.3, and 2.25.7. This vulnerability can be mitigated by disabling WMS dynamic styling and the Jiffle process. | |
| Title | GeoServer has an Infinite Loop Vulnerability in Jiffle process | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-10T15:16:31.100Z
Reserved: 2025-03-17T12:41:42.564Z
Link: CVE-2025-30145
Updated: 2025-06-10T15:16:19.470Z
Status : Analyzed
Published: 2025-06-10T15:15:24.070
Modified: 2025-08-26T16:11:23.463
Link: CVE-2025-30145
No data.
OpenCVE Enrichment
Updated: 2025-06-24T18:51:37Z
EUVD
Github GHSA