← volver
CVE-2024-36401criticalbajo ataqueCWE-95

Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver

100Vexday Risk Score

Corrige ahora. Ella está bajo explotación confirmada por CISA y tiene exploit funcional público.

ssvc Actcvss 9.8epss 100%
de la publicación al arma3 días
Publicada en NVD1 jul
1ª PoC+3d
metasploit1 jul
CISA KEV+14d
probabilidad de explotación
100%top 1% de las CVE
explotación observada
CISA + VulnCheck
48 exploit(s) público(s)
Acción exigida por CISAplazo federal: 2024-08-05

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Investigado y redactado con IA a partir del advisory del fabricante y análisis públicos, con las fuentes citadas. Verifica siempre la versión corregida en el advisory oficial antes de actuar.
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a default GeoServer installation due to unsafely evaluating property names as XPath expressions. The GeoTools library API that GeoServer calls evaluates property/attribute names for feature types in a way that unsafely passes them to the commons-jxpath library which can execute arbitrary code when evaluating XPath expressions. This XPath evaluation is intended to be used only by complex feature types (i.e., Application Schema data stores) but is incorrectly being applied to simple feature types as well which makes this vulnerability apply to **ALL** GeoServer instances. No public PoC is provided but this vulnerability has been confirmed to be exploitable through WFS GetFeature, WFS GetPropertyValue, WMS GetMap, WMS GetFeatureInfo, WMS GetLegendGraphic and WPS Execute requests. This vulnerability can lead to executing arbitrary code. Versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2 contain a patch for the issue. A workaround exists by removing the `gt-complex-x.y.jar` file from the GeoServer where `x.y` is the GeoTools version (e.g., `gt-complex-31.1.jar` if running GeoServer 2.25.1). This will remove the vulnerable code from GeoServer but may break some GeoServer functionality or prevent GeoServer from deploying if the gt-complex module is needed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
geoserver · geoserver
PoCs públicas encontradas48
githubgithub.com/whitebear-ch/GeoServerExploit121githubgithub.com/Chocapikk/CVE-2024-3640186githubgithub.com/Mr-xn/CVE-2024-3640156githubgithub.com/bmth666/GeoServer-Tools-CVE-2024-3640143githubgithub.com/ahisec/geoserver-43githubgithub.com/bigb0x/CVE-2024-3640134githubgithub.com/Niuwoo/CVE-2024-364014githubgithub.com/justin-p/geoexplorer4githubgithub.com/daniellowrie/CVE-2024-36401-PoC3githubgithub.com/URJACK2025/CVE-2024-364012githubgithub.com/amoy6228/CVE-2024-36401_Geoserver_RCE_POC2githubgithub.com/0x0d3ad/CVE-2024-364012githubgithub.com/punitdarji/GeoServer-CVE-2024-364011githubgithub.com/RevoltSecurities/CVE-2024-364011githubgithub.com/jakabakos/CVE-2024-36401-GeoServer-RCE0githubgithub.com/funnyDog896/CVE-2024-36401-WoodpeckerPlugin0githubgithub.com/y1s4s/CVE-2024-36401-PoC0githubgithub.com/kkhackz0013/CVE-2024-364010githubgithub.com/reveravip/Exploit-CVE-2024-364010githubgithub.com/mantanhacker/CVE-2024-36401-MASS0githubgithub.com/Delt-A/CVE-2024-36401-poc0githubgithub.com/DanieleGiovanardi2408/cve-2024-36401-geoserver-rce0vulncheckvulncheck.com/xdb/e2d5ed5bba08no verificadovulncheckvulncheck.com/xdb/9a3d3b1933bdno verificadovulncheckvulncheck.com/xdb/dd85e588e139no verificadovulncheckvulncheck.com/xdb/c70f778604ccno verificadovulncheckvulncheck.com/xdb/d7881a6b037bno verificadovulncheckvulncheck.com/xdb/e908c49bab48no verificadovulncheckvulncheck.com/xdb/07cf7a5d5e1bno verificadovulncheckvulncheck.com/xdb/0a69e625f39ano verificadovulncheckvulncheck.com/xdb/46abf92ec267no verificadovulncheckvulncheck.com/xdb/83b62ab68571no verificadovulncheckvulncheck.com/xdb/f4801e6b28d5no verificadovulncheckvulncheck.com/xdb/1dbce5a4766bno verificadovulncheckvulncheck.com/xdb/82eba5264bfbno verificadovulncheckvulncheck.com/xdb/432db9e70d9eno verificadovulncheckvulncheck.com/xdb/3d8baa68c24cno verificadovulncheckvulncheck.com/xdb/02f273d018e8no verificadovulncheckvulncheck.com/xdb/a4b1ddfc8280no verificadovulncheckvulncheck.com/xdb/8a38414bb4b7no verificadovulncheckvulncheck.com/xdb/6cff7d86193fno verificadovulncheckvulncheck.com/xdb/584a39f9a9cbno verificadovulncheckvulncheck.com/xdb/6cab2db287ebno verificadovulncheckvulncheck.com/xdb/e5537b0b1e67no verificadovulncheckvulncheck.com/xdb/b1faacbe8f25no verificadovulncheckvulncheck.com/xdb/fe7544c5185cno verificadovulncheckvulncheck.com/xdb/ff189f53f3e3no verificadovulncheckvulncheck.com/xdb/e651061f7feano verificado
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.