news.mlab.sh
Back to the feed
vulnerability

GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

Critical
Image: The Hacker News
Summary

A newly discovered zero-day SQL injection vulnerability in GeoServer is currently being actively exploited. The vulnerability, which has been assigned a GitHub security advisory identifier (GHSA-mqjf-5f49-2fjh), allows for remote code execution and has been observed with hundreds of exploitation attempts originating from a limited number of IP addresses. GeoServer versions 3.0.1, 2.28.5, and 2.27.6 have been released to address the issue.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.