漏洞描述
GeoServer Web Feature Service (WFS) is vulnerable to an XML External Entity (XXE) processing attack due to improper handling of XML input. This vulnerability allows attackers to perform Out-of-Band (OOB) data exfiltration and Server-Side Request Forgery (SSRF) by exploiting the GeoTools library.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/geonetwork/core-geonetwork/pull/8757↗github.comhttps://github.com/geonetwork/core-geonetwork/pull/8803↗github.comhttps://github.com/geoserver/geoserver/security/advisories/GHSA-jj54-8f66-c5pc↗github.comhttps://github.com/geotools/geotools/security/advisories/GHSA-826p-4gcg-35vw↗github.comhttps://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-2p76-gc46-5fvc↗github.comhttps://github.com/geonetwork/core-geonetwork/pull/8812↗docs.geoserver.orghttps://docs.geoserver.org/latest/en/user/production/config.html#production-config-external-entities↗