Critical GeoTools RCE Flaw Exploited in Geoserver Attacks

Red | Vulnerability Report

A critical Remote Code Execution (RCE) vulnerability in GeoTools, identified as CVE-2024-36404, has been disclosed. This 9.8 severity RCE vulnerability is caused by the unsafe evaluation of property names as XPath expressions. Another related flaw affecting GeoServer is CVE-2024-36401. This vulnerability stems from the GeoTools library API, which GeoServer relies on to evaluate property and attribute names for feature types.