CVE-2024-29198 is a high-severity Server-Side Request Forgery (SSRF) vulnerability affecting GeoServer, an open-source Java-based geospatial data server. This flaw allows unauthenticated attackers to make arbitrary requests from the server via the Demo request endpoint if the Proxy Base URL is not configured, potentially leading to information disclosure. With a CVSS score of 8.2 (HIGH), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required. While not currently listed in CISA's KEV catalog, exploit intelligence indicates the availability of Nuclei templates and community discussion suggests active interest, though no Metasploit or ExploitDB modules are present.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.24.4CPE matchmatch criteria | cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:* | ||
>= 2.25.0, < 2.25.2CPE matchmatch criteria | cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.