Record summary

CVE-2023-35042 has a selected CVSS score of 9.8 (critical).

Description

GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. NOTE: the vendor states that they are unable to reproduce this in any version.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 12, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 27, 2024 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
GitHub AdvisoryBefore 2.18.6 · Fixed in 2.18.6affected
2.19.0 to < 2.19.6 · Fixed in 2.19.6affected
2.20.0 to < 2.20.4 · Fixed in 2.20.4affected
GitHub AdvisoryBefore 2.18.6 · Fixed in 2.18.6affected
2.19.0 to < 2.19.6 · Fixed in 2.19.6affected
2.20.0 to < 2.20.4 · Fixed in 2.20.4affected
GitHub AdvisoryBefore 2.18.6 · Fixed in 2.18.6affected
2.19.0 to < 2.19.6 · Fixed in 2.19.6affected
2.20.0 to < 2.20.4 · Fixed in 2.20.4affected

References

6