Junglewise Threat Intelligence

CVE-2024-36401: Remote Code Execution (RCE) vulnerability in geoserver

CVE-2024-36401 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2024-07-01

Technologies: OSGeo GeoServer. Vendors: OSGeo.

Executive brief

OSGeo GeoServer and GeoTools are vulnerable to Remote Code Execution (RCE) due to unsafe evaluation of property names as XPath expressions via the commons-jxpath library. Unauthenticated attackers can exploit this through various OGC request parameters (e.g., WFS, WMS, WPS) to execute arbitrary code on the server.

Affected products

  • OSGeo GeoServer < 2.22.6, 2.23.0 to < 2.23.6, 2.24.0 to < 2.24.4, 2.25.0 to < 2.25.2
  • OSGeo GeoTools < 29.6, 30.0 to < 30.4, 31.0 to < 31.2

Timeline

  • 2024-07-15: disclosed
  • 2024-07-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-07-15: advisory

Related threats