geonetwork / geonetwork/core-geonetwork

Out-of-band resource load (HTTP)

Open
#2,001 5 comments 0 reactions 0 assignees View on GitHub
stale
Dominant language
Java
Stars
521
Forks
514
Avg merge
6d 13h
Merged PRs (30d)
19

Description

software component: GeoNetwork (opensource)
version: 3.2.1.0
test date: 21.04.2017

concerned parameter:
 /./proxy?url=http%3a%2f%2fn3r2z6ef1olo1igqbhvhqimbj2psdi19ozco.vie01.local%2fat.lfrz.discoveryservices%2fsrv%2fde%2fcsw202%3fservice%3dCSW%26request%3dGetCapabilities%26version%3d2.0.2
 /./proxy?url=http://www.xxxx.at%2fat.xxxx.discoveryservices%2fsrv%2fde%2fcsw202%3fservice%3dCSW%26request%3dGetCapabilities%26version%3d2.0.2
Proof-of-concept:
During proxy request, an URL is attached, which is dissolved via DNS by the system.
Additionally, it is possible to request any URLS.
![oob1](https://cloud.githubusercontent.com/assets/28924596/26404402/1501bd3e-4092-11e7-9a48-8e76c3feb19e.png)
![oob2](https://cloud.githubusercontent.com/assets/28924596/26404403/1507c454-4092-11e7-9c82-60da2e1acb76.png)

Contributor guide

Open the contributing guide

Research direction

Start by tracing the /proxy endpoint in GeoNetwork and reproduce the reported requests using the URLs from the issue. Determine how outbound destinations are handled and define completion as preventing unintended URL access while preserving intended proxy behavior, with regression coverage for the reported case.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
api, backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.