WPS Server Side Request Forgery in GeoServer
CVE-2023-43795
What is CVE-2023-43795?
GeoServer, an open source server for sharing and editing geospatial data, is susceptible to a Server Side Request Forgery vulnerability due to its handling of OGC Web Processing Service (WPS) requests. This weakness allows attackers to craft GET or POST requests that could exploit the server's trust and access internal resources or services. The issue has been resolved in GeoServer versions 2.22.5 and 2.23.2, highlighting the importance of updating to these patched versions to maintain security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
geoserver < 2.22.5 < 2.22.5
geoserver >= 2.23.0, < 2.23.2 < 2.23.0, 2.23.2
References
EPSS Score
89% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
