CVE-2021-40822
GeoServer allows SSRF via the option for setting a proxy host
Record summary
CVE-2021-40822 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC, 1 Nuclei template, and 1 lab environment.
Description
GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
GeoServerBrowse OSGeo / GeoServer | VulnCheck | Version data not supplied | |
org.geoserver:gs-mainBrowse Maven / org.geoserver:gs-main | GitHub Advisory | Through 2.18.5 | affected |
| 2.19.0 to ≤ 2.19.2 | affected | ||
Proofs of concept
1Repository PoCs
GitHubphor3nsic/CVE-2021-40822Repository PoCby phor3nsicStars: 2Not analyzed247 files
Docker lab environments
1GitHubdocker-compose.yaml
phor3nsic/CVE-2021-40822Created Analysis pendingCVE-2021-40822Compose · images
Packet coverage: some source evidence omitted
Nuclei templates
1ProjectDiscoveryHIGHGeoserver - Server-Side Request ForgeryCVSS 7.5
GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows server-side request forgery via the option for setting a proxy host.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to internal resources, data leakage, and potential remote code execution.
Remediation
Apply the latest security patches or updates provided by the Geoserver project to mitigate the SSRF vulnerability.
Source: ProjectDiscovery