>= 3.2.0, < 4.2.0
from 0, < a9eebae80cb362009660a1fd49e105e7cdb499b9 | >= 3.2.0, < 4.1.3
HIGH7.5CVE-2023-42439GeoNode vulnerable to SSRF Bypass to return internal host data >= 3.2.0, < 4.1.3.post1
HIGH7.5GeoNode vulnerable to SSRF Bypass to return internal host data
>= 3.2.0
MEDIUM6.5GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection
from 0, < 4.0.3
MEDIUM6.5GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection
from 0, < 2fdfe919f299b21f1609bf898f9dcfde58770ac0 | from 0, < 4.0.3
MEDIUM6.3GeoNode contains a server-side request forgery vulnerability in the service registration endpoint
>= 4.0.0, < 4.4.5
MEDIUM6.3GeoNode contains a server-side request forgery vulnerability in the service registration endpoint
>= 4.0.0, < 4.4.5, >= 5.0.0, < 5.0.2
MEDIUM6.3GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated users…
>= 4.0.0, < 4.4.5, >= 5.0.0, < 5.0.2
MEDIUM6.1GeoNode: Stored XSS to full account takeover
>= 3.2.1, < 4.2.3