Executive brief
OSGeo GeoServer and GeoTools are vulnerable to Remote Code Execution (RCE) due to unsafe evaluation of property names as XPath expressions via the commons-jxpath library. Unauthenticated attackers can exploit this through various OGC request parameters (e.g., WFS, WMS, WPS) to execute arbitrary code on the server.
Affected products
- OSGeo GeoServer < 2.22.6, 2.23.0 to < 2.23.6, 2.24.0 to < 2.24.4, 2.25.0 to < 2.25.2
- OSGeo GeoTools < 29.6, 30.0 to < 30.4, 31.0 to < 31.2
Timeline
- 2024-07-15: disclosed
- 2024-07-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-07-15: advisory