CVE-2023-26043

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-26043
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-26043.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-26043
Aliases
Related
Published
2023-02-27T21:15:12Z
Modified
2025-01-14T20:30:54Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. GeoNode is vulnerable to an XML External Entity (XXE) injection in the style upload functionality of GeoServer leading to Arbitrary File Read. This issue has been patched in version 4.0.3.

References

Affected packages

Git / github.com/geonode/geonode

Affected ranges

Type
GIT
Repo
https://github.com/geonode/geonode
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed