Record summary

CVE-2023-43795 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.

Description

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to process information from any server using GET and POST requests. This presents the opportunity for Server Side Request Forgery. This vulnerability has been patched in version 2.22.5 and 2.23.2.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 11, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE List< 2.22.5affected
>= 2.23.0, < 2.23.2affected

org.geoserver.extension:gs-wps-core

Browse Maven / org.geoserver.extension:gs-wps-core
GitHub AdvisoryBefore 2.22.5 · Fixed in 2.22.5affected
2.23.0 to < 2.23.2 · Fixed in 2.23.2affected

Nuclei templates

1
ProjectDiscoveryCRITICALGeoServer WPS - Server Side Request ForgeryCVSS 9.8

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to process information from any server using GET and POST requests. This presents the opportunity for Server Side Request Forgery. This vulnerability has been patched in version 2.22.5 and 2.23.2.

Impact

Unauthenticated attackers can exploit SSRF through the WPS service to make arbitrary HTTP requests and access internal network resources, potentially compromising the entire GeoServer infrastructure and accessing sensitive geospatial data.

Remediation

Update GeoServer to version 2.22.5 or 2.23.2 or later that validates URLs in WPS requests and restricts access to authorized external resources only.

WeaknessesCWE-918
AuthorsDhiyaneshDK
Template tagscve2023cvegeoserverssrfoastoososgeovkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*
Shodan: title:"GeoServer"
Shodan: http.title:"geoserver"
FOFA: app="GeoServer"
FOFA: app="geoserver"
FOFA: title="geoserver"
Google: intitle:"geoserver"

Source: ProjectDiscovery

References

5