Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2023-40017
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Geonode Server Side Request Forgery vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. In versions 3.2.0 through 4.1.2, the endpoint `/proxy/?url=` does not properly protect against server-side request forgery. This allows an attacker to port scan internal hosts and request information from internal hosts. A patch is available at commit a9eebae80cb362009660a1fd49e105e7cdb499b9.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
服务端请求伪造(SSRF)
Source: NVD (National Vulnerability Database)
Vulnerability Title
GeoNode 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GeoNode是一个开源平台,可促进地理空间数据的创建、共享和协作使用。 GeoNode 3.2.0至4.1.2版本存在代码问题漏洞,该漏洞源于端点/proxy/?url=存在服务器请求伪造(SSRF)漏洞。攻击者可利用该漏洞对内部主机进行端口扫描并发送请求信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
GeoNodegeonode >= 3.2.0, <= 4.1.2 -
II. Public POCs for CVE-2023-40017
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2023-40017
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2023-40017

No comments yet


Leave a comment