Record summary

CVE-2021-40822 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC, 1 Nuclei template, and 1 lab environment.

Description

GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1
Lab environments
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
GitHub AdvisoryThrough 2.18.5affected
2.19.0 to ≤ 2.19.2affected

Proofs of concept

1

Repository PoCs

GitHubphor3nsic/CVE-2021-40822Repository PoCby phor3nsicStars: 2Not analyzed247 files

828.8 KiB

GitHub

PoC details

Docker lab environments

1
GitHub

docker-compose.yaml

phor3nsic/CVE-2021-40822Created
Analysis pendingCVE-2021-40822Compose · images

1 Compose manifest · 1 service

Structural lab evidence is available; analysis is pending.

Packet coverage: some source evidence omitted

Nuclei templates

1
ProjectDiscoveryHIGHGeoserver - Server-Side Request ForgeryCVSS 7.5

GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows server-side request forgery via the option for setting a proxy host.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to internal resources, data leakage, and potential remote code execution.

Remediation

Apply the latest security patches or updates provided by the Geoserver project to mitigate the SSRF vulnerability.

WeaknessesCWE-918
AuthorsFor3stCo1d, aringo-bf
Template tagscve2021cvessrfgeoserverosgeovkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*
Shodan: title:"GeoServer"
Shodan: http.title:"geoserver"
FOFA: app="GeoServer"
FOFA: app="geoserver"
FOFA: title="geoserver"
Google: intitle:"geoserver"

Source: ProjectDiscovery

References

6