Impact
The vulnerability is located in the _is_within_roots function of OpenGeoS GeoLibre up to version 2.3.0. An attacker can craft input that coerces the server to perform outbound HTTP requests to arbitrary URLs. This results in a classic server‑side request forgery, allowing the attacker to reach internal network resources or exfiltrate data from the host machine. The weakness is documented as CWE‑918 and carries a CVSS score of 6.9, indicating medium risk to confidentiality and integrity.
Affected Systems
Systems running OpenGeoS GeoLibre earlier than version 2.4.0 are affected. The fix was introduced in release 2.4.0, so any deployment using 2.3.0 or earlier should be reviewed for this flaw.
Risk and Exploitability
The flaw can be triggered remotely, potentially through exposed API endpoints or web interfaces that invoke the vulnerable function. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known exploitation yet. However, because the attack path is remote and the impact could expose internal systems or data, the risk remains moderate. Mitigating measures such as vendor patching or restricting outbound requests are recommended to reduce exposure.
OpenCVE Enrichment