Critical GeoTools RCE Flaw Exploited in Geoserver Attacks

Threat Level – Red | Vulnerability Report
Download PDF

A critical Remote Code Execution (RCE) vulnerability in GeoTools, identified as CVE-2024-36404, has been disclosed. This 9.8 severity RCE vulnerability is caused by the unsafe evaluation of property names as XPath expressions. Another related flaw affecting GeoServer is CVE-2024-36401. This vulnerability stems from the GeoTools library API, which GeoServer relies on to evaluate property and attribute names for feature types.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox