Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

GeoServer vulnerable to SSRF in TestWfsPost for specific targets, e.g. PHP + Nginx

GHSA-68cf-j696-wvv9

Published ยท Modified

Description

Summary

Missing checks allow for SSRF to specific targets using the TestWfsPost enpoint.

Mitigation

To manage the proxy base value as a system administrator, use the parameter PROXY_BASE_URL to provide a non-empty value that cannot be overridden by the user interface or incoming request.thomsmith.

Resolution

The TestWfsPost has been replaced in GeoServer 2.25.2 and GeoServer 2.24.4 with a JavaScript Demo Requests page to test OGC Web Services.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes