Missing checks allow for SSRF to specific targets using the TestWfsPost enpoint.
To manage the proxy base value as a system administrator, use the parameter PROXY_BASE_URL
to provide a non-empty value that cannot be overridden by the user interface or incoming request.thomsmith.
The TestWfsPost has been replaced in GeoServer 2.25.2 and GeoServer 2.24.4 with a JavaScript Demo Requests page to test OGC Web Services.
{ "github_reviewed_at": "2025-06-10T20:17:58Z", "cwe_ids": [ "CWE-918" ], "nvd_published_at": null, "severity": "HIGH", "github_reviewed": true }