{"id":"GHSA-8g7v-vjrc-x4g5","summary":"GeoServer log file path traversal vulnerability","details":"### Impact\n\nThis vulnerability requires GeoServer Administrator with access to the admin console  to misconfigured the **Global Settings** for **log file location** to an arbitrary location.\n\nThis can be used to read files via the admin console **GeoServer Logs** page. It is also possible to leverage RCE or cause denial of service by overwriting key GeoServer files.\n\n### Patches\n\nThis issue has been addressed in GeoServer 3.0.0:\n* The Global Settings page can no longer be used to specify log file location\n* The application parameter ``GEOSERVER_LOG_LOCATION`` mechanism (outlined below) is now the only approach available to customize the log file location.\n\n### Workarounds\n\nA system administrator responsible for running GeoServer can define  the ``GEOSERVER_LOG_FILE`` parameter, preventing the global setting provided from being used.\n\nThe ``GEOSERVER_LOG_LOCATION`` parameter can be set as system property, environment variable, or servlet context parameter.\n\nEnvironmental variable:\n```bash\nexport GEOSERVER_LOG_LOCATION=/var/opt/geoserver/logs\n```\n\nSystem property:\n```bash\n-DGEOSERVER_LOG_LOCATION=/var/opt/geoserver/logs\n```\n\nWeb application ``WEB-INF/web.xml``:\n```xml\n  \u003ccontext-param\u003e\n    \u003cparam-name\u003e GEOSERVER_LOG_LOCATION \u003c/param-name\u003e\n    \u003cparam-value\u003e/var/opt/geoserver/logs\u003c/param-value\u003e\n  \u003c/context-param\u003e\n```\n\nTomcat **conf/Catalina/localhost/geoserver.xml**:\n```xml\n\u003cContext\u003e\n  \u003cParameter name=\"GEOSERVER_LOG_LOCATION\"\n             value=\"/var/opt/geoserver/logs\" override=\"false\"/\u003e\n\u003c/Context\u003e\n```\n\n### References\n\n* [Upgrading GeoServer 3](https://docs.geoserver.org/main/en/user/installation/upgrade3/#log-location-configuration)\n* [Log location](https://docs.geoserver.org/latest/en/user/configuration/globalsettings/#logging-settings) (User Manual)","aliases":["CVE-2023-41877"],"modified":"2026-07-20T13:45:23.705538130Z","published":"2024-03-20T14:45:21Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-03-20T14:45:21Z","nvd_published_at":"2024-03-20T15:15:07Z","cwe_ids":["CWE-22"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/geoserver/geoserver/security/advisories/GHSA-8g7v-vjrc-x4g5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-41877"},{"type":"WEB","url":"https://docs.geoserver.org/latest/en/user/configuration/globalsettings.html#log-location"},{"type":"PACKAGE","url":"https://github.com/geoserver/geoserver"}],"affected":[{"package":{"name":"org.geoserver:gs-main","ecosystem":"Maven","purl":"pkg:maven/org.geoserver/gs-main"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.23.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-8g7v-vjrc-x4g5/GHSA-8g7v-vjrc-x4g5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}