Aller au contenu principal
CRITICAL

CVE-2025-30220

CVSS v3

9.9

CRITICAL

Score EPSS

42.3 %

probabilité d’exploitation au 2026-10-05

CISA KEV

Non

exploitation connue

Exploitation

—

statut SSVC

Description

GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also imp

Détails techniques

Publiée le
2025-06-10
Dernière modification
2025-08-26

Questions fréquentes

Qu’est-ce que CVE-2025-30220 ?

GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also imp

CVE-2025-30220 est-elle activement exploitée ?

Aucune exploitation active de CVE-2025-30220 n’est confirmée. Son score EPSS était de 42.3 % au 2026-10-05, soit la probabilité estimée d’exploitation dans les 30 prochains jours.

Quel est le score CVSS de CVE-2025-30220 ?

CVE-2025-30220 a un score de base CVSS v3 de 9.9 (gravité CRITICAL).

CVE-2025-30220 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 50 vérifications gratuites par mois · Clé API gratuite