by @jakaba
12 Jul 2024

GeoServer RCE (CVE-2024-36401)

by @jakaba
12 Jul 2024

GeoServer RCE (CVE-2024-36401)

CVEs

9.8 Critical Severity

Apps

Geoserver
GeoserverGeoserver
G
GeotoolsGeotools

Screenshots from the blog posts

images/clyinfknzgc5p1gn6d5v354n1.jpgimages/clyinfknzgc5p1gn6d5v354n1.jpg

Summary

The GeoServer RCE vulnerability (CVE-2024-36401) arises from an insecure manner in which the GeoTools library API, utilized by GeoServer, passes attribute names of element types to the commons-jxpath library.

Description

users/photos/clj8b3h1k16g10uoihwvzgsxi.png

@jakaba

74 posts

Total vcoins

0

Social media links

Comments (0)