Potential vulnerability bypassing GWC data security

Description

In certain GeoServer configuration setups, it's possible to bypass the "Enable Data Security" option in GeoWebCache and gain access to cached WMS tiles that should be private.

I can provide more detailed information on the types of configurations that exhibit this issue, but since this could be considered a security issue, I thought I'd see how you wanted to proceed first. I also have a potential patch for this bug that I can share. So let me know if you'd like for me to share more details and the patch in private or in public.

Thanks!

Environment

None

Activity

n 
November 11, 2016 at 5:18 PM

FYI: This was fixed by https://github.com/geoserver/geoserver/pull/1727 and released in 2.9.1 and 2.8.5, so this can be closed.

Fixed

Details

Assignee

Reporter

Triage

Fix versions

Affects versions

Components

Priority

Created July 13, 2016 at 7:18 AM
Updated November 14, 2016 at 4:56 PM
Resolved November 14, 2016 at 4:56 PM