CVE-2021-40822: SSRF
Published May 1, 2022
·Updated
GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.
Affected Software
2 affected components
OSGeo GeoServer<=2.18.5
OSGeo GeoServer>=2.19.0<2.19.3
Remediation
Event History
May 1, 2022
CVE Published
via MITRE·11:17 PM
Data Sourced
via MITRE·11:17 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-40822.
2
What is the severity of CVE-2021-40822?
The severity of CVE-2021-40822 is high with a score of 7.5.
3
What software versions are affected by CVE-2021-40822?
Versions 2.18.5 and 2.19.0 through 2.19.2 of GeoServer are affected by CVE-2021-40822.
4
What is the vulnerability description for CVE-2021-40822?
CVE-2021-40822 is a Server Side Request Forgery (SSRF) vulnerability in GeoServer that allows SSRF via the option for setting a proxy host.
5
How can I fix CVE-2021-40822?
To fix CVE-2021-40822, upgrade GeoServer to version 2.19.3 or later.