GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.
| Software | From | Fixed in |
|---|---|---|
| osgeo / geoserver | - | 2.18.5.x |
| osgeo / geoserver | 2.19.0 | 2.19.3 |
org.geoserver / gs-main
|
- | 2.18.5.x |
org.geoserver / gs-main
|
2.19.0 | 2.19.2.x |