CVE-2024-41120

CVSS v3.1 9.8 (Critical)
98% Progress
EPSS 0.06 % (26th)
0.06% Progress
Affected Products 1
NVD Status Analyzed

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the url variable on line 63 of pages/9_?_Vector_Data_Visualization.py takes user input, which is later passed to the gpd.read_file method. gpd.read_file method creates a request to arbitrary destinations, leading to blind server-side request forgery. Commit c4f81d9616d40c60584e36abb15300853a66e489 fixes this issue.

Weaknesses
CWE-20
Improper Input Validation
CWE-918
Server-Side Request Forgery (SSRF)
CVE Status
PUBLISHED
NVD Status
Analyzed
CNA
GitHub, Inc.
Published Date
2024-07-26 21:15:14
(6 weeks ago)
Updated Date
2024-08-26 17:33:33
(12 days ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Opengeos Streamlit-geospatial prior 2024-07-19 version cpe:2.3:a:opengeos:streamlit-geospatial < 2024-07-19
Loading...
Loading...
Loading...
Loading...
Loading...