S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jul 17, 2025

CVE-2024-29198 Scanner

CVE-2024-29198 Scanner - Server-Side-Request-Forgery (SSRF) vulnerability in GeoServer

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.6k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-29198
8.2
CVSShigh
Exploitable remotely over the internet · no authentication required.

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It possible to achieve Service Side Request Forgery (SSRF) via the Demo request endpoint if Proxy Base URL has not been set. Upgrading to GeoServer 2.24.4, or 2.25.2, removes the TestWfsPost servlet resolving this issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
geoserverby geoserver
>= 2.0.0, < 2.24.4
Updated Aug 22, 2026View on NVD →
Detail

GeoServer is an open-source server used by geographic information systems to share, process, and edit geospatial data. It is widely adopted by both government agencies and commercial enterprises for building systems that need web-based maps and geographical data services. Developers utilize GeoServer to transform raw geospatial data into Google Earth overlays, Web Map Service (WMS) images, and other accessible formats. Organizations also employ it to make geographic data public and extend data interactivity on their websites. It enables organizations to leverage the standardized protocols for integration with various map applications, facilitating professional and accurate map presentations.

The Server-Side-Request-Forgery (SSRF) vulnerability in GeoServer arises when an attacker uses the Demo request endpoint inappropriately if the Proxy Base URL is not configured. SSRF vulnerabilities allow an attacker to send crafted requests from a vulnerable application to unintended destinations, potentially exposing critical backend systems. In GeoServer's case, this vulnerability could lead to the enumeration of internal network services and unauthorized access to sensitive data hosted within cloud environments. By manipulating a server's function, malicious attackers can reach resources meant to be restricted from users, underlining a serious security gap. Organizations need to be aware of such potential oversights to ensure that they don't leave internal resources inadvertently exposed.

This SSRF vulnerability can be exploited through the TestWfsPost endpoint in the GeoServer. The vulnerability occurs when an unauthenticated user crafts a POST request that the server processes, due to the absence of proper Proxy Base URL configuration. Attackers can specify a URL in the request's body, prompting the server to initiate requests to locations specified by the attacker. The attack vector is HTTP-based, and the malicious request contains HTTP payloads crafted to bypass input validation and gain access to restricted information. Correctly configured Proxy Base URLs are crucial to mitigate such risks.

When exploited, the SSRF vulnerability could allow attackers to access sensitive internal resources by bypassing network restrictions commonly assumed to be enforced by firewalls. This vulnerability could expose an organization's internal network topology to discovery, leading to lateral attacks targeting more critical and sensitive systems. Additionally, in cloud-hosted instances, there is the risk of exposing credentials or accessing metadata services that can divulge confidential configurations and tokens. It poses a substantial threat, enabling attackers to further infiltrate the internal networks or launch additional attacks using the compromised server.

REFERENCES

Solution Advice
  • Upgrade GeoServer to the latest patched version to close off the SSRF vulnerability.
  • Properly configure the Proxy Base URL in your GeoServer setup to ensure safe handling of server requests.
  • Regularly audit system configurations to verify adherence to best security practices regarding URL handling and server requests.
  • Implement network-level protections to restrict unauthorized access to internal resources from GeoServer instances.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.