5
CVSSv2

CVE-2021-40822

Published: 02/05/2022 Updated: 09/05/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

GeoServer up to and including 2.18.5 and 2.19.x up to and including 2.19.2 allows SSRF via the option for setting a proxy host.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

osgeo geoserver

Github Repositories

Welcome to my blog! About: About Last Posts: Another vision for SSRF SSRF Geoserver (CVE-2021-40822) Object Injection to SQL Injection Bug bounty profiles: Hackerone Bugcrowd

CVE-2021-40822 SSRF GeoServer Article: gccybermonkscom/posts/cve-2021-40822/ Lab: Clone this repository: # git clone githubcom/phor3nsic/CVE-2021-40822git Start Lab: # cd CVE-2021-40822 && docker-compose up Check if this target is vulnerable: # python3 CVE-2021-40