GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue.
| Vendor | Product | Versions |
|---|---|---|
| geoserver | org.geoserver.extension:gs-db2 | < 2.27.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| open source | geoserver | cert_advisory | 90% |
Updated affected versions to include 2.26.x, changed severity to MEDIUM, and noted that no exploit exists.
Initial creation