From giovanni.allegri at geosolutionsgroup.com Mon Jan 26 08:02:30 2026 From: giovanni.allegri at geosolutionsgroup.com (Giovanni Allegri) Date: Mon, 26 Jan 2026 17:02:30 +0100 Subject: [GeoNode-devel] GeoServer Patches 2.24 In-Reply-To: References: Message-ID: Sorry for the very late reply Henning. Geoserver for GeoNode is safe thanks to Geofence, which doesn't allow those requests. The block is at the source code level, so it's ssfe whatever the Geofence configuration. Giovanni == GeoServer Professional Services from the experts! Visit http://bit.ly/gs-services-us for more information. == Dott. Giovanni Allegri Technical Lead / Project Manager GeoSolutions Group phone: +39 0584 962313 cell: +39 345 2815774 fax: +39 0584 1660272 https://www.geosolutionsgroup.com/ http://twitter.com/geosolutions_it ------------------------------------------------------- Con riferimento alla normativa sul trattamento dei dati personali (Reg. UE 2016/679 - Regolamento generale sulla protezione dei dati ?GDPR?), si precisa che ogni circostanza inerente alla presente email (il suo contenuto, gli eventuali allegati, etc.) ? un dato la cui conoscenza ? riservata al/i solo/i destinatario/i indicati dallo scrivente. Se il messaggio Le ? giunto per errore, ? tenuta/o a cancellarlo, ogni altra operazione ? illecita. Le sarei comunque grato se potesse darmene notizia. This email is intended only for the person or entity to which it is addressed and may contain information that is privileged, confidential or otherwise protected from disclosure. We remind that - as provided by European Regulation 2016/679 ?GDPR? - copying, dissemination or use of this e-mail or the information herein by anyone other than the intended recipient is prohibited. If you have received this email by mistake, please notify us immediately by telephone or e-mail. Il ven 19 dic 2025, 17:19 Bredel, Henning via geonode-devel < geonode-devel at lists.osgeo.org> ha scritto: > Hey, > > GeoServer [disclosed a CVE]( > https://github.com/geoserver/geoserver/security) some weeks ago: > > - [CVE-2025-58360]( > https://github.com/geoserver/geoserver/security/advisories/GHSA-fjf5-xgmq-5525 > ) > > Is it safe to use 2.24.4 referenced by the geonode-project [0]. I am not > aware of any fixes/patches in geonode-docker or elsewhere. Did I miss > something? > > Best > > Henning > > > [0] > https://github.com/GeoNode/geonode-project/blob/f5824531e3cb23d7899d6446bac3530bbfb69b58/.env.sample#L13 > > > -- > > Henning > Bredel > adesso SE > Klaus-Bungert-Stra?e 5 > > 40468 D?sseldorf > > > T +49 211 740759-00 > M +49 151 56463626 > E henning.bredel at adesso.de > www.adesso.de > blog.adesso.de > ------------------------------------------------------- > >>> business. people. technology. <<< > ------------------------------------------------------- > > adesso SE mit Sitz in Dortmund > Vorstand: Mark Lohweber (Vors.), Benedikt Bonnmann, Kristina Gerwert, > Michael Knopp, > Andreas Prenneis > Vorsitzender des Aufsichtsrates: Prof. Dr. Volker Gruhn > Amtsgericht Dortmund HRB 20663 > _______________________________________________ > geonode-devel mailing list > geonode-devel at lists.osgeo.org > https://lists.osgeo.org/mailman/listinfo/geonode-devel > -------------- next part -------------- An HTML attachment was scrubbed... URL: From giovanni.allegri at geosolutionsgroup.com Tue Jan 27 00:46:35 2026 From: giovanni.allegri at geosolutionsgroup.com (Giovanni Allegri) Date: Tue, 27 Jan 2026 09:46:35 +0100 Subject: [GeoNode-devel] GeoServer Patches 2.24 In-Reply-To: References: Message-ID: Harald, The CVE is still present but ineffective for a standard GeoNode deployment because, as I said, the vulnerability is blocked by Geofence. Anyway, you can upgrade to Geoserver 2.27.4 on GeoNode 4.4.x. It's not officially supported, but it's proven to work fine. Giovanni On Tue, Jan 27, 2026 at 9:31?AM Harald von Waldow < harald.vonwaldow at thuenen.de> wrote: > Hello Giovanni, > > Geoserver instances running 2.24.4-v2 (GeoNode Docker image) were > flagged by BSI as vulnerable ("Software verwundbar f?r CVE-2025-58360. > Nachweis erfolgte mittels Proof-of-Concept."). Not sure what to make of > that. > > Best > Harald > > On Mon, 2026-01-26 at 17:02 +0100, Giovanni Allegri via geonode-devel > wrote: > > Sorry for the very late reply Henning. > > Geoserver for GeoNode is safe thanks to Geofence, which doesn't allow > > those requests. > > > > The block is at the source code level, so it's ssfe whatever the > > Geofence configuration. > > > > Giovanni > > > > == > > GeoServer Professional Services from the experts! > > Visit http://bit.ly/gs-services-us for more information. > > == > > > > Dott. Giovanni Allegri > > Technical Lead / Project Manager > > > > GeoSolutions Group > > phone: +39 0584 962313 > > cell: +39 345 2815774 > > fax: +39 0584 1660272 > > > > https://www.geosolutionsgroup.com/ > > http://twitter.com/geosolutions_it > > ------------------------------------------------------- > > > > Con riferimento alla normativa sul trattamento dei dati personali > > (Reg. UE 2016/679 - Regolamento generale sulla protezione dei dati > > ?GDPR?), si precisa che ogni circostanza inerente alla presente email > > (il suo contenuto, gli eventuali allegati, etc.) ? un dato la cui > > conoscenza ? riservata al/i solo/i destinatario/i indicati dallo > > scrivente. Se il messaggio Le ? giunto per errore, ? tenuta/o a > > cancellarlo, ogni altra operazione ? illecita. Le sarei comunque > > grato se potesse darmene notizia. > > > > This email is intended only for the person or entity to which it is > > addressed and may contain information that is privileged, > > confidential or otherwise protected from disclosure. We remind that - > > as provided by European Regulation 2016/679 ?GDPR? - copying, > > dissemination or use of this e-mail or the information herein by > > anyone other than the intended recipient is prohibited. If you have > > received this email by mistake, please notify us immediately by > > telephone or e-mail. > > > > Il ven 19 dic 2025, 17:19 Bredel, Henning via geonode-devel > > ha scritto: > > > > > > > > > Hey, > > > > > > > > > GeoServer [disclosed a > > > CVE](https://github.com/geoserver/geoserver/security) some weeks > > > ago: > > > > > > > > > - [CVE-2025- > > > 58360](https://github.com/geoserver/geoserver/security/advisories/G > > > HSA-fjf5-xgmq-5525) > > > > > > > > > Is it safe to use 2.24.4 referenced by the geonode-project [0]. I > > > am not aware of any fixes/patches in geonode-docker or elsewhere. > > > Did I miss something? > > > > > > > > > Best > > > > > > > > > Henning > > > > > > > > > > > > > > > [0] > > > > https://github.com/GeoNode/geonode-project/blob/f5824531e3cb23d7899d6446bac3530bbfb69b58/.env.sample#L13 > > > > > > > > > > > > > > > > > > > > > -- > > > > > > Henning Bredel > > > adesso SE > > > > > > Klaus-Bungert-Stra?e 5 > > > 40468 D?sseldorf > > > > > > > > > T +49 211 740759-00 > > > M +49 151 56463626 > > > E henning.bredel at adesso.de > > > > > > www.adesso.de > > > > > > blog.adesso.de > > > ------------------------------------------------------- > > > >>> business. people. technology. <<< > > > ------------------------------------------------------- > > > > > > adesso SE mit Sitz in Dortmund > > > Vorstand: Mark Lohweber (Vors.), Benedikt Bonnmann, Kristina > > > Gerwert, Michael Knopp, > > > Andreas Prenneis > > > Vorsitzender des Aufsichtsrates: Prof. Dr. Volker Gruhn > > > Amtsgericht Dortmund HRB 20663 > > > _______________________________________________ > > > geonode-devel mailing list > > > geonode-devel at lists.osgeo.org > > > https://lists.osgeo.org/mailman/listinfo/geonode-devel > > _______________________________________________ > > geonode-devel mailing list > > geonode-devel at lists.osgeo.org > > https://lists.osgeo.org/mailman/listinfo/geonode-devel > > -- > Dr. Harald von Waldow > Senior Research Data Specialist > Th?nen Institute > Centre for Information Management > Bundesallee 44 > 38116 Braunschweig, Germany > Web: https://thuenen.de > > The Johann Heinrich von Th?nen Institute, Federal Research Institute > for Rural Areas, Forestry and Fisheries ? Th?nen Institute in brief - > consists of 15 specialized institutes with socioeconomic, ecological > and technological expertise. The Th?nen Institute conducts research and > policy advice related to rural areas, agriculture, forests and > fisheries. > > > -- == GeoServer Professional Services from the experts! Visit http://bit.ly/gs-services-us for more information. == Dott. Giovanni Allegri Technical Lead / Project Manager GeoSolutions Group phone: +39 0584 962313 cell: +39 345 2815774 fax: +39 0584 1660272 https://www.geosolutionsgroup.com/ http://twitter.com/geosolutions_it ------------------------------------------------------- Con riferimento alla normativa sul trattamento dei dati personali (Reg. UE 2016/679 - Regolamento generale sulla protezione dei dati ?GDPR?), si precisa che ogni circostanza inerente alla presente email (il suo contenuto, gli eventuali allegati, etc.) ? un dato la cui conoscenza ? riservata al/i solo/i destinatario/i indicati dallo scrivente. Se il messaggio Le ? giunto per errore, ? tenuta/o a cancellarlo, ogni altra operazione ? illecita. Le sarei comunque grato se potesse darmene notizia. This email is intended only for the person or entity to which it is addressed and may contain information that is privileged, confidential or otherwise protected from disclosure. We remind that - as provided by European Regulation 2016/679 ?GDPR? - copying, dissemination or use of this e-mail or the information herein by anyone other than the intended recipient is prohibited. If you have received this email by mistake, please notify us immediately by telephone or e-mail. -------------- next part -------------- An HTML attachment was scrubbed... URL: