CISA Warns of Actively Exploited RCE Flaw in GeoServer GeoTools Software

Based on proof of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a major security issue affecting OSGeo GeoServer GeoTools to its list of known exploited vulnerabilities (KEV) on Monday.

GeoServer is an open-source Java software server that facilitates the sharing and editing of geospatial data. It is the Web Coverage Service (WCS) and Web Feature Service (WFS) reference implementation from the Open Geospatial Consortium (OGC).

This vulnerability, identified as CVE-2024-36401 (CVSS score: 9.8), is related to a potential remote code execution scenario that might be initiated by intentionally manipulating input.

According to a warning published by the project maintainers earlier this month, several OGC request parameters unsafely evaluate property names as XPath expressions read more about CISA Warns of Actively Exploited RCE Flaw in GeoServer GeoTools Software.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *