cve/2024/CVE-2024-41118.md
2024-08-05 18:41:32 +00:00

1.1 KiB

CVE-2024-41118

Description

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the url variable on line 47 of pages/7_📦_Web_Map_Service.py takes user input, which is passed to get_layers function, in which url is used with get_wms_layer method. get_wms_layer method creates a request to arbitrary destinations, leading to blind server-side request forgery. Commit c4f81d9616d40c60584e36abb15300853a66e489 fixes this issue.

POC

Reference

Github

No PoCs found on GitHub currently.