GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
WatchTowr has confirmed active exploitation attempts against a critical SQL injection vulnerability in GeoServer, which allows for remote code execution when specific PostGIS configurations are used. Although the flaw was initially reported without a CVE identifier, the vendor has since issued patches in versions 3.0.1, 2.28.5, and 2.27.6, assigning the issue the identifier GHSA-mqjf-5f49-2fjh with a CVSS score of 9.8.
The vulnerability stems from improper escaping in the jsonArrayContains function within the GeoTools library, enabling attackers to inject malicious SQL commands. This represents a regression of previously fixed issues, specifically CVE-2023-25158. Organizations are strongly advised to upgrade to the latest patched versions immediately to mitigate the risk of system compromise.