TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions prior to 4.0.3 allows an attacker to proxy domains not explicitly allowed in the `proxyableDomains` configuration. Version 4.0.3 fixes the issue.
References
Configurations
History
No history.
Information
Published : 2026-02-26 00:16
Updated : 2026-03-04 21:12
NVD link : CVE-2026-27818
Mitre link : CVE-2026-27818
CVE.ORG link : CVE-2026-27818
JSON object : View
Products Affected
terria
- terriajs-server
