Skip to content
COOEY

EXPOSURES › CVE-2024-36401

CVE-2024-36401

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-07-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-36401 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatchedsupply-chain

OSGeo GeoServer's GeoTools component allows unauthenticated remote code execution via unsafely evaluated XPath expressions.

This unpatched vulnerability enables attackers to execute arbitrary code without authentication, posing a severe risk to DIB systems relying on GeoServer for geospatial data management. The fact that it is actively exploited in the KEV list indicates it is currently being weaponized in the wild, requiring immediate patching and configuration hardening to prevent unauthorized access to sensitive geospatial datasets.

Shame score — An unauthenticated RCE vulnerability in a widely used geospatial server component that is already actively exploited in the wild represents a critical failure in security hygiene and vendor responsibility.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.