CISA Warns of Actively Exploited RCE Flaw in GeoServer GeoTools Software
ID: 39351251-fd39-5b47-a314-5c60420e6e38
STIX ID: report--39351251-fd39-5b47-a314-5c60420e6e38
Feed Name: The Hacker News
CISA added a critical RCE vulnerability in OSGeo GeoServer/GeoTools (CVE-2024-36401, CVSS 9.8) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation; GeoServer maintainers released fixes (2.23.6, 2.24.4, 2.25.2) and federal agencies were ordered to patch by August 5, 2024. A related critical GeoTools XPath-evaluation flaw (CVE-2024-36404) was also patched, and the report references active weaponization of a separate Ghostscript RCE (CVE-2024-29510), underscoring immediate risk to systems exposing affected services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
