S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Aug 10, 2024

CVE-2024-36401 Scanner

CVE-2024-36401 scanner - Remote Code Execution (RCE) vulnerability in GeoServer

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
7
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-36401
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a default GeoServer installation due to unsafely evaluating property names as XPath expressions. The GeoTools library API that GeoServer calls evaluates property/attribute names for feature types in a way that unsafely passes them to the commons-jxpath library which can execute arbitrary code when evaluating XPath expressions. This XPath evaluation is intended to be used only by complex feature types (i.e., Application Schema data stores) but is incorrectly being applied to simple feature types as well which makes this vulnerability apply to **ALL** GeoServer instances. No public PoC is provided but this vulnerability has been confirmed to be exploitable through WFS GetFeature, WFS GetPropertyValue, WMS GetMap, WMS GetFeatureInfo, WMS GetLegendGraphic and WPS Execute requests. This vulnerability can lead to executing arbitrary code. Versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2 contain a patch for the issue. A workaround exists by removing the `gt-complex-x.y.jar` file from the GeoServer where `x.y` is the GeoTools version (e.g., `gt-complex-31.1.jar` if running GeoServer 2.25.1). This will remove the vulnerable code from GeoServer but may break some GeoServer functionality or prevent GeoServer from deploying if the gt-complex module is needed.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
geoserverby geoserver
>= 2.23.0, < 2.23.6
geoserverby geoserver
AFFECTED< 2.23.6SAFE ✓≥ 2.23.6
geoserverby geoserver
AFFECTED< 2.24.4SAFE ✓≥ 2.24.4
geoserverby geoserver
AFFECTED< 2.25.2SAFE ✓≥ 2.25.2
Updated Aug 22, 2026View on NVD →
Detail

GeoServer is an open-source server written in Java that allows users to share, process, and edit geospatial data. It is widely used in geographic information system (GIS) applications by governmental organizations, research institutions, and commercial enterprises. The software supports numerous data formats and serves as a hub for geographic data that can be used in various analysis and mapping applications. Its extensibility and support for standard OGC protocols make it a popular choice for managing and distributing geographic information. Users typically install GeoServer in environments where reliable access to geospatial data is critical.

The vulnerability in GeoServer, specifically in versions prior to 2.25.1, 2.24.3, and 2.23.5, allows unauthenticated remote code execution (RCE) due to improper evaluation of property names as XPath expressions. Attackers can craft specific input to exploit this flaw in the GeoServer's default configuration. Successful exploitation allows execution of arbitrary code, which could compromise the entire server and potentially lead to further attacks. The severity of this vulnerability makes it a critical issue that requires immediate attention.

The vulnerability exists in the OGC request parameters of GeoServer, where property names are unsafely evaluated as XPath expressions. This occurs when the system processes WFS requests that include specific, maliciously crafted input. The vulnerable endpoint is MapPreviewPage, and the vulnerable parameter is typeNames, which is manipulated to execute code on the server. The flaw arises because GeoServer fails to properly sanitize inputs before processing them as part of these property name expressions. This weakness allows attackers to execute arbitrary shell commands remotely.

If exploited, this vulnerability could allow attackers to execute arbitrary code on the GeoServer instance. This could lead to a full system compromise, including data theft, service disruption, and the installation of backdoors. Attackers might also use this foothold to move laterally within the network, targeting other systems. Additionally, sensitive geospatial data managed by GeoServer could be manipulated, deleted, or exfiltrated, causing significant disruption to the organization's operations.

By using the S4E platform, users can proactively identify and mitigate critical vulnerabilities like this RCE in GeoServer before they are exploited by attackers. The platform's comprehensive scanning and detailed reports empower users to stay ahead of potential threats. Regular updates and an extensive library of checks ensure that your digital assets are continuously protected against emerging vulnerabilities. Joining S4E means you gain access to a robust defense against a wide range of cyber threats, safeguarding your sensitive data and maintaining your organization's security posture.

References:

Solution Advice
  • Upgrade GeoServer to versions 2.25.1, 2.24.3, or 2.23.5 or later where this vulnerability is patched.
  • Restrict access to GeoServer to trusted users only, especially when using sensitive configuration pages.
  • Implement input validation to ensure that all user inputs are properly sanitized and do not allow for arbitrary code execution.
  • Monitor and review logs for any suspicious activity that might indicate exploitation attempts.
  • Regularly update your GeoServer instance and apply security patches as soon as they are available.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.