GHSA-rmxg-6qqf-x8mr

    Dashboard / Vulnerabilities / GHSA-rmxg-6qqf-x8mr

    GHSA-rmxg-6qqf-x8mr

    Published: 21 Nov 2024Last Modified: 10 Sept 2026

    Summary: GeoNode Server Side Request forgery

    Details: ### Summary A server side request forgery vuln was found within geonode when testing on a bug bounty program. Server side request forgery allows a user to request information on the internal service/services. ### Details The endpoint /proxy/?url= does not properly protect against SSRF. when using the following format you can request internal hosts and display data. /proxy/?url=http://169.254.169.254\@whitelistedIPhere. This will state wether the AWS internal IP is alive. If you get a 404, the host is alive. A non alive host will not display a response. To display metadata, use a hashfrag on the url /proxy/?url=http://169.254.169.254\@#whitelisteddomain.com or try /proxy/?url=http://169.254.169.254\@%23whitelisteddomain.com ### Impact Port scan internal hosts, and request information from internal hosts.

    Affected packages

    Package

    Name: geonode

    Purl: pkg:pypi/geonode

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 3.2.0
    Fixed -4.2.0

    Affected versions

    3.2.0
    3.2.1
    3.2.2
    3.2.3
    3.2.3.post1
    3.2.4

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-rmxg-6qqf-x8mr | CVE-DB