CyberzSOC

Publication detail
← Back to advisories & guidance

2024-068: Critical Vulnerabilities in GeoServer and GeoTools ↗ source

July 11, 2024 CERT-EU Advisory

Summary

These vulnerabilities can result in arbitrary code execution through the unsafe evaluation of user-supplied XPath expressions [1,2,3]. The vulnerability CVE-2024-36401, with a CVSS score of 9.8, allows Remote Code Execution (RCE) flaw by unauthenticated users via specially crafted input to a default GeoServer installation. This issue arises from the unsafe evaluation of property names as XPath expressions due to a flaw in the GeoTools library API, which GeoServer relies upon [1]. The vulnerability CVE-2024-36404, with a CVSS score of 9.8, is a Remote Code Execution (RCE) flaw against the GeoTools library. This vulnerability occurs when certain methods use the commons-jxpath library to evaluate XPath expressions supplied within user inputs. The commons-jxpath library has the capability to execute arbitrary code embedded within these CVE-2024-36401 affects the following packages CVE-2024-36404 affects the following packages CERT-EU strongly recommends updating to the latest versions by following the instructions GeoServer has issued a workaround and mitigation measures depending on the release version.

News Coverage

DateSourceArticle
2026-07-22 SANS Internet Storm Center Rondo Meets Geoserver, (Wed, Jul 22nd) CVE-2024-36401
2026-06-24 Kaspersky Securelist StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader CVE-2024-36401

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-36401 9.8 Critical OSGeo GeoServer OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating pro…
CVE-2024-36404 9.8 Critical geotools geotools GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.