Executive brief
OSGeo GeoServer JAI-EXT contains a code injection vulnerability where Jiffle scripts provided via network requests are compiled into Java code via Janino and executed. This allows remote attackers to achieve arbitrary code execution on the underlying system.
Affected products
- GeoSolutionsGroup JAI-EXT < 1.1.22
- OSGeo GeoServer
Timeline
- 2022-04-13: disclosed: NVD Published Date
- 2024-06-26: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-06-26: exploited: Reported as exploited in the wild per CISA KEV entry