S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-24816 Scanner

CVE-2022-24816 scanner - Remote Code Execution (RCE) vulnerability in JAI-EXT

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-24816
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compile Jiffle scripts from the final application, by removing janino-x.y.z.jar from the classpath.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
jai-extby geosolutions-it
< 1.1.22
jai-extby geosolutionsgroup
AFFECTED< 1.1.22SAFE ✓≥ 1.1.22
Updated Aug 22, 2026View on NVD →
Detail

JAI-EXT is an open-source project that aims to extend the Java Advanced Imaging (JAI) API, which is used in Java-based image processing and analysis applications. Specifically, JAI-EXT adds a number of new functionality to JAI, expanding its capabilities beyond those offered in the core library. This includes support for additional image formats, advanced warping and resampling, and more.

Recently, however, a serious vulnerability was detected in JAI-EXT, known as CVE-2022-24816. This vulnerability allows an attacker to inject malicious code into Jiffle scripts, which are compiled into Java code via Janino and executed. This means that an attacker could potentially execute remote code on a target system, giving them significant control over the system and any data stored on it.

If exploited, this vulnerability can lead to a wide range of malicious activity, including remote code execution, data theft, and other types of attacks. The potential impact of this vulnerability is significant, given that many applications rely on JAI-EXT to perform critical image processing and analysis tasks. As such, it is important that users take steps to protect themselves against this vulnerability.

At s4e.io, we are committed to providing our users with the tools and information they need to protect their digital assets from vulnerabilities like CVE-2022-24816. With our pro features, users can quickly and easily identify any vulnerabilities in their systems and take the necessary steps to address them. So if you want to protect yourself against the latest threats and stay one step ahead of the hackers, sign up for s4e.io today.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that can be taken to mitigate the risks associated with CVE-2022-24816. These include:

  • Upgrading to the latest version of JAI-EXT, which contains a patch that disables the ability to inject malicious code into Jiffle scripts.
  • Removing janino-x.y.z.jar from the classpath, which negates the ability to compile Jiffle scripts from the final application.
  • Ensuring that all software and operating systems are kept up-to-date with the latest security patches.
  • Using a firewall to restrict network access and prevent unauthorized access to sensitive resources.
  • Implementing strong access controls and authentication mechanisms, such as password policies and two-factor authentication.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.