GeoServer Zero-Day Exploited Hours After Disclosure
TL;DR. Threat actors are actively exploiting an unpatched GeoServer zero-day vulnerability just hours after its public disclosure, allowing for remote code execution. - The SQL injection flaw in GeoServer's jsonArrayContains function affects geospatial data processing across multiple industries. - WatchTowr observed hundreds of exploitation attempts originating from a few source IP addresses shortly after the vulnerability became public. - GeoServer has a history of being targeted, with this new zero-day requiring immediate action by organizations to restrict public access.
- Threat actors are exploiting an unpatched GeoServer zero-day vulnerability.
- The flaw allows remote code execution via SQL injection in the jsonArrayContains function.
- Exploitation attempts began within hours of the public disclosure by researcher q1uf3ng.
- Organizations using GeoServer must restrict public access and monitor for a vendor fix due to immediate active exploitation.
Sources
- Hackers Exploiting Unpatched GeoServer Zero-Day — securityweek.com