Vulnerabilities > CVE-2021-40822 - Server-Side Request Forgery (SSRF) vulnerability in Osgeo Geoserver

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
osgeo
CWE-918

Summary

GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.

Vulnerable Configurations

Part Description Count
Application
Osgeo
150

Common Weakness Enumeration (CWE)