GeoServer Zero-Day Exploited Hours After Disclosure

TL;DR. Threat actors are actively exploiting an unpatched GeoServer zero-day vulnerability just hours after its public disclosure, allowing for remote code execution. - The SQL injection flaw in GeoServer's jsonArrayContains function affects geospatial data processing across multiple industries. - WatchTowr observed hundreds of exploitation attempts originating from a few source IP addresses shortly after the vulnerability became public. - GeoServer has a history of being targeted, with this new zero-day requiring immediate action by organizations to restrict public access.

Sources

Back to QLANKR News