← voltar
CVE-2024-36401criticalsob ataqueCWE-95

Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver

100Vexday Risk Score

Corrija agora. Ela está sob exploração confirmada pelo CISA e tem exploit funcional público.

ssvc Actcvss 9.8epss 100%
da publicação à arma3 dias
Publicada no NVD1 de jul.
1ª PoC+3d
metasploit1 de jul.
CISA KEV+14d
probabilidade de exploração
100%top 1% das CVEs
exploração observada
simCISA + VulnCheck
48 exploit(s) público(s)
Ação exigida pela CISAprazo federal: 2024-08-05

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Pesquisado e redigido com IA a partir do advisory do fornecedor e de análises públicas, com as fontes acima. Confira sempre a versão corrigida no advisory oficial antes de agir.
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a default GeoServer installation due to unsafely evaluating property names as XPath expressions. The GeoTools library API that GeoServer calls evaluates property/attribute names for feature types in a way that unsafely passes them to the commons-jxpath library which can execute arbitrary code when evaluating XPath expressions. This XPath evaluation is intended to be used only by complex feature types (i.e., Application Schema data stores) but is incorrectly being applied to simple feature types as well which makes this vulnerability apply to **ALL** GeoServer instances. No public PoC is provided but this vulnerability has been confirmed to be exploitable through WFS GetFeature, WFS GetPropertyValue, WMS GetMap, WMS GetFeatureInfo, WMS GetLegendGraphic and WPS Execute requests. This vulnerability can lead to executing arbitrary code. Versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2 contain a patch for the issue. A workaround exists by removing the `gt-complex-x.y.jar` file from the GeoServer where `x.y` is the GeoTools version (e.g., `gt-complex-31.1.jar` if running GeoServer 2.25.1). This will remove the vulnerable code from GeoServer but may break some GeoServer functionality or prevent GeoServer from deploying if the gt-complex module is needed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
geoserver · geoserver
PoCs públicas encontradas48
githubgithub.com/whitebear-ch/GeoServerExploit121githubgithub.com/Chocapikk/CVE-2024-3640186githubgithub.com/Mr-xn/CVE-2024-3640156githubgithub.com/bmth666/GeoServer-Tools-CVE-2024-3640143githubgithub.com/ahisec/geoserver-43githubgithub.com/bigb0x/CVE-2024-3640134githubgithub.com/Niuwoo/CVE-2024-364014githubgithub.com/justin-p/geoexplorer4githubgithub.com/daniellowrie/CVE-2024-36401-PoC3githubgithub.com/URJACK2025/CVE-2024-364012githubgithub.com/amoy6228/CVE-2024-36401_Geoserver_RCE_POC2githubgithub.com/0x0d3ad/CVE-2024-364012githubgithub.com/punitdarji/GeoServer-CVE-2024-364011githubgithub.com/RevoltSecurities/CVE-2024-364011githubgithub.com/jakabakos/CVE-2024-36401-GeoServer-RCE0githubgithub.com/funnyDog896/CVE-2024-36401-WoodpeckerPlugin0githubgithub.com/y1s4s/CVE-2024-36401-PoC0githubgithub.com/kkhackz0013/CVE-2024-364010githubgithub.com/reveravip/Exploit-CVE-2024-364010githubgithub.com/mantanhacker/CVE-2024-36401-MASS0githubgithub.com/Delt-A/CVE-2024-36401-poc0githubgithub.com/DanieleGiovanardi2408/cve-2024-36401-geoserver-rce0vulncheckvulncheck.com/xdb/e2d5ed5bba08não verificadovulncheckvulncheck.com/xdb/9a3d3b1933bdnão verificadovulncheckvulncheck.com/xdb/dd85e588e139não verificadovulncheckvulncheck.com/xdb/c70f778604ccnão verificadovulncheckvulncheck.com/xdb/d7881a6b037bnão verificadovulncheckvulncheck.com/xdb/e908c49bab48não verificadovulncheckvulncheck.com/xdb/07cf7a5d5e1bnão verificadovulncheckvulncheck.com/xdb/0a69e625f39anão verificadovulncheckvulncheck.com/xdb/46abf92ec267não verificadovulncheckvulncheck.com/xdb/83b62ab68571não verificadovulncheckvulncheck.com/xdb/f4801e6b28d5não verificadovulncheckvulncheck.com/xdb/1dbce5a4766bnão verificadovulncheckvulncheck.com/xdb/82eba5264bfbnão verificadovulncheckvulncheck.com/xdb/432db9e70d9enão verificadovulncheckvulncheck.com/xdb/3d8baa68c24cnão verificadovulncheckvulncheck.com/xdb/02f273d018e8não verificadovulncheckvulncheck.com/xdb/a4b1ddfc8280não verificadovulncheckvulncheck.com/xdb/8a38414bb4b7não verificadovulncheckvulncheck.com/xdb/6cff7d86193fnão verificadovulncheckvulncheck.com/xdb/584a39f9a9cbnão verificadovulncheckvulncheck.com/xdb/6cab2db287ebnão verificadovulncheckvulncheck.com/xdb/e5537b0b1e67não verificadovulncheckvulncheck.com/xdb/b1faacbe8f25não verificadovulncheckvulncheck.com/xdb/fe7544c5185cnão verificadovulncheckvulncheck.com/xdb/ff189f53f3e3não verificadovulncheckvulncheck.com/xdb/e651061f7feanão verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.