In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.
Start learningUpgrade pygeoapi to version 0.23.3 or higher.
pygeoapi is a pygeoapi provides an API to geospatial data
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the subscriber process. An attacker can access internal HTTP services by submitting specially crafted OGC API - Process execution requests that leverage the subscriber object.
This vulnerability can be mitigated by disabling process-based resources in the application configuration.