Tag: GeoTools Software

CISA Warns of Actively Exploited RCE Flaw in GeoServer GeoTools Software
News

CISA Warns of Actively Exploited RCE Flaw in GeoServer GeoTools Software

Based on proof of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a major security issue affecting OSGeo GeoServer GeoTools to its list of known exploited vulnerabilities (KEV) on Monday. GeoServer is an open-source Java software server that facilitates the sharing and editing of geospatial data. It is the Web Coverage Service (WCS) and Web Feature Service (WFS) reference implementation from the Open Geospatial Consortium (OGC). This vulnerability, identified as CVE-2024-36401 (CVSS score: 9.8), is related to a potential remote code execution scenario that might be initiated by intentionally manipulating input. According to a warning published by the project maintainers earlier this month, several OGC request parameters unsafely evaluat...