Описание
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. In versions 3.2.0 through 4.1.2, the endpoint /proxy/?url= does not properly protect against server-side request forgery. This allows an attacker to port scan internal hosts and request information from internal hosts. A patch is available at commit a9eebae80cb362009660a1fd49e105e7cdb499b9.
Ссылки
- Patch
- ExploitThird Party Advisory
- Patch
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 3.2.0 (включая) до 4.1.2 (включая)
cpe:2.3:a:geosolutionsgroup:geonode:*:*:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00085
Низкий
7.5 High
CVSS3
Дефекты
CWE-918
Связанные уязвимости
EPSS
Процентиль: 25%
0.00085
Низкий
7.5 High
CVSS3
Дефекты
CWE-918