Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GeoNode is vulnerable to an XML External Entity (XXE) injection #10462

Closed
afabiani opened this issue Dec 21, 2022 · 0 comments
Closed

GeoNode is vulnerable to an XML External Entity (XXE) injection #10462

afabiani opened this issue Dec 21, 2022 · 0 comments
Assignees
Labels
4.0.x 4.1.x master security Pull requests that address a security vulnerability

Comments

@afabiani
Copy link
Member

Issue: XML External Entity (XXE) injection in GeoServer style upload functionality (GHSL-2022-129)

@afabiani afabiani added security Pull requests that address a security vulnerability master 4.1.x labels Dec 21, 2022
@afabiani afabiani self-assigned this Dec 21, 2022
@afabiani afabiani added the 4.0.x label Dec 21, 2022
afabiani added a commit that referenced this issue Dec 22, 2022
afabiani added a commit that referenced this issue Dec 22, 2022
afabiani added a commit that referenced this issue Dec 22, 2022
…th expression (#10465)

* [Fixes #10462] GeoNode is vulnerable to an XML External Entity (XXE) injection

* [Fixes #10464] Fix code scanning alert - Uncontrolled data used in path expression
github-actions bot pushed a commit that referenced this issue Dec 22, 2022
…th expression (#10465)

* [Fixes #10462] GeoNode is vulnerable to an XML External Entity (XXE) injection

* [Fixes #10464] Fix code scanning alert - Uncontrolled data used in path expression
github-actions bot pushed a commit that referenced this issue Dec 22, 2022
…th expression (#10465)

* [Fixes #10462] GeoNode is vulnerable to an XML External Entity (XXE) injection

* [Fixes #10464] Fix code scanning alert - Uncontrolled data used in path expression
afabiani added a commit that referenced this issue Dec 22, 2022
…th expression (#10465) (#10468)

* [Fixes #10462] GeoNode is vulnerable to an XML External Entity (XXE) injection

* [Fixes #10464] Fix code scanning alert - Uncontrolled data used in path expression

Co-authored-by: Alessio Fabiani <[email protected]>
afabiani added a commit that referenced this issue Dec 22, 2022
…th expression (#10465) (#10469)

* [Fixes #10462] GeoNode is vulnerable to an XML External Entity (XXE) injection

* [Fixes #10464] Fix code scanning alert - Uncontrolled data used in path expression

Co-authored-by: Alessio Fabiani <[email protected]>
alaeddine-farhat pushed a commit to alaeddine-farhat/geonode that referenced this issue Jun 7, 2023
…d in path expression (GeoNode#10465) (GeoNode#10468)

* [Fixes GeoNode#10462] GeoNode is vulnerable to an XML External Entity (XXE) injection

* [Fixes GeoNode#10464] Fix code scanning alert - Uncontrolled data used in path expression

Co-authored-by: Alessio Fabiani <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
4.0.x 4.1.x master security Pull requests that address a security vulnerability
Projects
None yet
Development

No branches or pull requests

1 participant