It is possible to achieve Server Side Request Forgery (SSRF) via the Demo request endpoint if Proxy Base URL has not been set. An unauthenticated user can supply a request that will be issued by the server, allowing enumeration of internal networks and, in the case of cloud instances, access to sensitive data.
id: CVE-2024-29198
info:
name: GeoServer Demo Request Endpoint - Server Side Request Forgery
au
...