Summary
Missing checks allow for SSRF to specific targets using the TestWfsPost enpoint.
Mitigation
To manage the proxy base value as a system administrator, use the parameter PROXY_BASE_URL
to provide a non-empty value that cannot be overridden by the user interface or incoming request.thomsmith.
Resolution
The TestWfsPost has been replaced in GeoServer 2.25.2 and GeoServer 2.24.4 with a JavaScript Demo Requests page to test OGC Web Services.
References
Summary
Missing checks allow for SSRF to specific targets using the TestWfsPost enpoint.
Mitigation
To manage the proxy base value as a system administrator, use the parameter
PROXY_BASE_URL
to provide a non-empty value that cannot be overridden by the user interface or incoming request.thomsmith.Resolution
The TestWfsPost has been replaced in GeoServer 2.25.2 and GeoServer 2.24.4 with a JavaScript Demo Requests page to test OGC Web Services.
References