Описание
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. GeoNode is vulnerable to an XML External Entity (XXE) injection in the style upload functionality of GeoServer leading to Arbitrary File Read. This issue has been patched in version 4.0.3.
Ссылки
- Patch
- ExploitThird Party Advisory
- Patch
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.0.3 (исключая)
cpe:2.3:a:geosolutionsgroup:geonode:*:*:*:*:*:*:*:*
EPSS
Процентиль: 57%
0.00357
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-611
CWE-611
Связанные уязвимости
CVSS3: 6.5
github
больше 1 года назад
GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection
EPSS
Процентиль: 57%
0.00357
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-611
CWE-611