VYPR
High severityNVD Advisory· Published Aug 24, 2023· Updated Oct 2, 2024

Geonode Server Side Request Forgery vulnerability

CVE-2023-40017

Description

GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. In versions 3.2.0 through 4.1.2, the endpoint /proxy/?url= does not properly protect against server-side request forgery. This allows an attacker to port scan internal hosts and request information from internal hosts. A patch is available at commit a9eebae80cb362009660a1fd49e105e7cdb499b9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
geonodePyPI
>= 3.2.0, < 4.2.04.2.0

Affected products

2
  • ghsa-coords
    Range: >= 3.2.0, < 4.2.0
  • GeoNode/geonodev5
    Range: >= 3.2.0, <= 4.1.2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.