OSGeo Vulnerabilities and Affected Products
Vulnerabilities associated with JAI-EXT.
Products
Clear product| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-24816CRITICAL | Improper Control of Generation of Code in jai-extJAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compi… | CVSS10.0v3.1 | EPSS98.7% | PoCs1 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |