Hackers exploit unpatched GeoServer zero-day

Hackers exploit unpatched GeoServer zero-day

According to WatchTowr, an attack surface management company, threat actors began exploiting an unpatched zero-day vulnerability in GeoServer within hours of its publication.

The security flaw, described as a SQL injection issue that could be exploited for remote code execution (RCE), was disclosed on Wednesday by a security researcher named q1uf3ng.

According to the researcher post On It can be used with PostGIS and Oracle JDBC data stores.

SQL injection is likely caused by user-supplied arguments not being properly sanitized before being encoded into database queries, leading to RCE under certain configurations.

According to WatchTowr, threat actors began exploiting the unpatched zero-day vulnerability shortly after it became public.

“We began monitoring exploitation attempts within hours of publication and have since recorded hundreds of attempts from a small number of source IP addresses. Another example of how quickly attackers act once a vulnerability becomes publicly available,” said WatchTowr’s Jake Knott.

Advertising. Scroll to continue reading.

Threat actors specifically exploited the vulnerability to investigate vulnerable systems, but no follow-up activity was observed.

“However, this is unlikely to remain the case for long: GeoServer has a track record of being attacked and exploited on a large scale, with several vulnerabilities listed in the CISA Known Exploited Vulnerabilities catalog,” Knott said.

“With no patch currently available and exploitation already underway, organizations deploying GeoServer should take this vulnerability seriously and, where possible, identify exposed instances, restrict public access and seek vendor remediation,” he added.

GeoServer is a popular open source geospatial data exchange and processing platform used in government, agriculture, telecommunications, transportation, and other industries.

Related: Adobe Commerce bug was targeted immediately after disclosure

Related: WordPress 7.0.4 fixes remote code execution vulnerability

Related: Fortinet fixes authentication errors in FortiWeb and FortiManager

Related: Critical vulnerability in VMware vCenter in attackers’ crosshairs

Leave a Reply

Your email address will not be published. Required fields are marked *