← Back to CVEs
CVE-2023-41339
HIGH8.6
Description
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The WMS specification defines an ``sld=<url>`` parameter for GetMap, GetLegendGraphic and GetFeatureInfo operations for user supplied "dynamic styling". Enabling the use of dynamic styles, without also configuring URL checks, provides the opportunity for Service Side Request Forgery. This vulnerability can be used to steal user NetNTLMv2 hashes which could be relayed or cracked externally to gain further access. This vulnerability has been patched in versions 2.22.5 and 2.23.2.
CVE Details
CVSS v3.1 Score8.6
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published10/25/2023
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
osgeo:geoserver
Weaknesses (CWE)
CWE-918CWE-918
References
https://github.com/geoserver/geoserver/releases/tag/2.22.5(security-advisories@github.com)
https://github.com/geoserver/geoserver/releases/tag/2.23.2(security-advisories@github.com)
https://github.com/geoserver/geoserver/security/advisories/GHSA-cqpc-x2c6-2gmf(security-advisories@github.com)
https://github.com/geoserver/geoserver/releases/tag/2.22.5(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/geoserver/geoserver/releases/tag/2.23.2(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/geoserver/geoserver/security/advisories/GHSA-cqpc-x2c6-2gmf(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.