EXPOSURES › CVE-2024-36401
CVE-2024-36401
HIGH ⌖ ON CISA KEV · EXPLOITEDOSGeo GeoServer's GeoTools component allows unauthenticated remote code execution via unsafely evaluated XPath expressions.
This unpatched vulnerability enables attackers to execute arbitrary code without authentication, posing a severe risk to DIB systems relying on GeoServer for geospatial data management. The fact that it is actively exploited in the KEV list indicates it is currently being weaponized in the wild, requiring immediate patching and configuration hardening to prevent unauthorized access to sensitive geospatial datasets.
Shame score — An unauthenticated RCE vulnerability in a widely used geospatial server component that is already actively exploited in the wild represents a critical failure in security hygiene and vendor responsibility.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input.