Junglewise Threat Intelligence

CVE-2022-24816: Improper Control of Generation of Code ('Code Injection') in jai-ext

CVE-2022-24816 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2023-09-19

Technologies: OSGeo GeoServer. Vendors: Maven, OSGeo.

Executive brief

OSGeo GeoServer JAI-EXT contains a code injection vulnerability where Jiffle scripts provided via network requests are compiled into Java code via Janino and executed. This allows remote attackers to achieve arbitrary code execution on the underlying system.

Affected products

  • GeoSolutionsGroup JAI-EXT < 1.1.22
  • OSGeo GeoServer

Timeline

  • 2022-04-13: disclosed: NVD Published Date
  • 2024-06-26: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-06-26: exploited: Reported as exploited in the wild per CISA KEV entry