// For flags

CVE-2023-42439

GeoNode SSRF Bypass to return internal host data

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. A SSRF vulnerability exists starting in version 3.2.0, bypassing existing controls on the software. This can allow a user to request internal services for a full read SSRF, returning any data from the internal network. The application is using a whitelist, but the whitelist can be bypassed. The bypass will trick the application that the first host is a whitelisted address, but the browser will use `@` or `%40` as a credential to the host geoserver on port 8080, this will return the data to that host on the response. Version 4.1.3.post1 is the first available version that contains a patch.

GeoNode es una plataforma de código abierto que facilita la creación, el intercambio y el uso colaborativo de datos geoespaciales. Existe una vulnerabilidad SSRF a partir de la versión 3.2.0, que pasa por alto los controles existentes en el software. Esto puede permitir a un usuario solicitar servicios internos para un SSRF de lectura completa, devolviendo cualquier dato de la red interna. La aplicación utiliza una lista blanca, pero se puede omitir la lista blanca. La omisión engañará a la aplicación diciéndole que el primer host es una dirección incluida en la lista blanca, pero el navegador usará `@` o `%40` como credencial para el geoservidor del host en el puerto 8080, lo que devolverá los datos a ese host en la respuesta. La versión 4.1.3.post1 es la primera versión disponible que contiene un parche.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
Poc
Automatable
Yes
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-09-08 CVE Reserved
  • 2023-09-15 CVE Published
  • 2024-09-21 EPSS Updated
  • 2024-09-25 CVE Updated
  • 2024-09-25 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Geosolutionsgroup
Search vendor "Geosolutionsgroup"
Geonode
Search vendor "Geosolutionsgroup" for product "Geonode"
>= 3.2.0 < 4.1.3
Search vendor "Geosolutionsgroup" for product "Geonode" and version " >= 3.2.0 < 4.1.3"
-
Affected