Rondo Meets Geoserver, (Wed, Jul 22nd)
ID: edb2565a-fa61-5058-84c1-c1cf6688a1b7
STIX ID: report--edb2565a-fa61-5058-84c1-c1cf6688a1b7
Feed Name: SANS ISC Diary
A GeoServer XPath expression evaluation vulnerability (CVE-2024-36401) was actively exploited: an observed GET request used a crafted GetPropertyValue valueReference to exec a shell command that base64-decoded to a wget/curl one-liner fetching and executing a Rondo botnet script from 45.153.34.153. The report includes the original encoded request, the decoded command, and notes that Rondo has targeted GeoServer previously; evidence is from server logs showing the attack and the resulting (possibly removed) payload.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
