A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2024-36401

OSGeo GeoServer GeoTools Eval Injection Vulnerability

Published
2024-07-15
Modified
2026-07-31
Sources
cisa-kev

Summary

OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.