GeoServer
cpe:2.3:a:geoserver:geoserver:*:*:*:*:*:*:*
- < 2.26.0
A server-side request forgery (SSRF) vulnerability has been identified in GeoServer versions prior to 2.26.0. The issue arises in the Coverage REST API, specifically within the endpoint that allows file uploads from a specified URL. This functionality, available through the 'url' method, lacks proper validation, enabling potential exploitation by uploading malicious files from unverified sources.
Exploitation of this vulnerability allows for server-side request forgery, where an attacker can manipulate the server to make requests on their behalf, potentially leading to unauthorized data access or interaction with internal services.
Users can upgrade to GeoServer version 2.26.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.