GeoServer RCE Attack
ID: c0ff1ddf-c16e-5d72-9b4a-d13cb62fddc4
STIX ID: report--c0ff1ddf-c16e-5d72-9b4a-d13cb62fddc4
Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts
Threat Score
A critical remote code execution vulnerability (CVE-2024-36401) in GeoServer is being actively exploited and has been observed across 40,000+ FortiGuard sensors; FortiGuard Recon attributes the activity to the Earth Baxia APT group, and CISA has listed the flaw in its Known Exploited Vulnerabilities catalog. The issue stems from inadequate input validation in request handling and poses a significant risk of system compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
