QID 730773

Date Published: 2023-04-05

QID 730773: GeoServer Server Side Request Forgery (SSRF) Vulnerability

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.

Affected Versions:
GeoServer versions through 2.18.5
GeoServer versions from 2.19.0 and prior to version 2.19.3

QID Detection Logic (Unauthenticated): This QID checks for vulnerable GeoServer versions by extracting the version from webpage.

Successful exploitation of this vulnerability could lead to a security breach or could affect confidentiality, integrity, and availability.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Vendor has released patches. For more information please refer to -4GeoServer Releases

    Vendor References

    CVEs related to QID 730773

    Software Advisories
    Advisory ID Software Component Link
    GeoServer Releases URL Logo github.com/geoserver/geoserver/compare/2.19.2...2.19.3