TL;DR
GeoServer maintainers disclosed a CVSS 10 GeoServer Cloud vulnerability in a GitHub Actions workflow. It could have let an outside contributor run code on the build runner and steal repository secrets. The maintainers have removed the workflow and found no sign of abuse.
CISA KEV isn't the only exploit signal. Pro/Team adds a second confirmed-exploit feed.
Try free for 14 daysWhy This GeoServer Cloud Vulnerability Matters
GeoServer is an open source Java server for sharing and editing geospatial data. The flaw sits in the build pipeline of the geoserver-cloud repository, not in the software users install. Still, CI/CD flaws are a classic path to supply chain attacks. Stolen tokens with write access could let an attacker push malicious code into a trusted project.
How the Attack Works
The sonarcloud-fork-pr.yaml workflow used the pull_request_target trigger. That trigger runs with the repository’s own permissions and secrets. The workflow then checked out code from the incoming pull request and built it.
As a result, anyone opening a pull request from a fork could have their code run in a privileged context. The GeoServer security advisory warns this created a “possibility of exfiltrating repository secrets including those with write permissions over the repository.”
Affected Scope and Exploitation Status
The issue affected the geoserver-cloud repository’s CI setup on the main and release/2.28.x branches. No CVE has been assigned. The maintainers’ review found no abuse. The workflow “only ran for fork PRs from known community contributors with ordinary, non-malicious changes.” They also found no new artifacts published to the OSGeo Nexus during the exposure window. Release downloads are built on a separate server, not GitHub Actions.
Remediation
The team rewrote the workflow using the GitHub Security Lab “Preventing pwn requests” pattern, and deleted the vulnerable file from every branch. They are also rotating secrets. GeoServer users do not need to patch. However, projects using pull_request_target should audit their own workflows for the same GeoServer Cloud vulnerability pattern.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!