GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.
References
Link Resource
https://github.com/geoserver/geoserver/compare/2.19.2...2.19.3 Patch Release Notes Third Party Advisory
https://github.com/geoserver/geoserver/releases Release Notes Third Party Advisory
https://osgeo-org.atlassian.net/browse/GEOS-10229 Issue Tracking Vendor Advisory
https://osgeo-org.atlassian.net/browse/GEOS-10229?focusedCommentId=83508 Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-05-01T23:17:25

Updated: 2022-05-01T23:17:25

Reserved: 2021-09-09T00:00:00


Link: CVE-2021-40822

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-05-02T00:15:08.113

Modified: 2022-05-09T19:17:59.593


Link: CVE-2021-40822

JSON object: View

cve-icon Redhat Information

No data.

CWE