CVERadar
Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For FreeCVE-2024-36401
Critical Severity|Geoserver
92
SVRS
9.8
CVSSv3
0.99787
EPSS
TAGS
In The WildExploit AvaliableCISA KEVExploit Available
VECTOR STRING
CVSS:3.1AV:NAC:LPR:NUI:NS:UC:HI:HA:H
PUBLICATION DATE2024-07-01
LAST MODIFIED2025-10-21
Deep CVE Analysis in Progress
The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.
Security Intelligence Brief
1. What is this vulnerability and why does it matter?
This vulnerability, identified as CVE-2024-36401, affects GeoServer, an open-source server for sharing and editing geospatial data. It allows for unauthenticated Remote Code Execution (RCE) due to insecure evaluation of property names as XPath expressions. This is critical because it enables an unauthenticated attacker to execute arbitrary code on the server, potentially leading to full system compromise, data theft, service disruption, or further network penetration. The vulnerability impacts all GeoServer instances, making it a widespread and severe threat.
2. What are the CVSS score, severity level, and disclosure details?
The CVSS score for this vulnerability is 9.8, which translates to a Critical severity level. The vulnerability was published on 2024-07-01 15:25:41 UTC and last modified on 2025-10-21 22:56:21 UTC.
3. Which products, vendors, systems, and versions are affected?
This vulnerability affects GeoServer, an open-source product. Specifically, all versions of GeoServer prior to the following patched releases are vulnerable:
- 2.22.6
- 2.23.6
- 2.24.4
- 2.25.2
4. What is the technical root cause and attack vector?
The technical root cause lies within the GeoTools library API, which GeoServer utilizes. This library evaluates property/attribute names for feature types in a way that unsafely passes them to the `commons-jxpath` library. The `commons-jxpath` library can execute arbitrary code when evaluating XPath expressions. While this XPath evaluation is intended only for complex feature types (e.g., Application Schema data stores), it is incorrectly applied to simple feature types as well, making virtually all GeoServer installations susceptible. The attack vector involves sending specially crafted OGC request parameters to a vulnerable GeoServer instance.
5. How can this vulnerability be exploited?
This vulnerability can be exploited by unauthenticated users through specially crafted input against a default GeoServer installation. The exploitation occurs by sending malicious XPath expressions embedded within OGC request parameters. No public Proof of Concept (PoC) is explicitly provided in the CVE data, but it has been confirmed that this vulnerability is exploitable through the following OGC request types:
- WFS GetFeature
- WFS GetPropertyValue
- WMS GetMap
- WMS GetFeatureInfo
- WMS GetLegendGraphic
- WPS Execute requests
6. What mitigation steps and patches are available?
The primary mitigation is to upgrade GeoServer to a patched version. The following versions contain a fix for this issue:
- 2.22.6
- 2.23.6
- 2.24.4
- 2.25.2
7. How can vulnerable systems be detected?
Vulnerable systems can be detected by identifying GeoServer installations running versions older than the patched releases (2.22.6, 2.23.6, 2.24.4, or 2.25.2). Administrators should check the GeoServer version number. Additionally, the presence of the `gt-complex-x.y.jar` file (where `x.y` corresponds to the GeoTools version) in a GeoServer installation that has not been patched or had the workaround applied indicates potential vulnerability. Network scans or web application vulnerability scanners configured to identify specific GeoServer versions or patterns in OGC request handling might also detect vulnerable instances.
8. What are the indicators of compromise (IOCs)?
Indicators of Compromise (IOCs) for this vulnerability, given its Remote Code Execution nature, could include:
- Unusual process activity: Detection of unexpected processes running on the GeoServer host, especially those spawned by the GeoServer application's user.
- Suspicious network connections: Outbound network connections from the GeoServer process to unusual or unauthorized external IP addresses.
- File system modifications: Creation, modification, or deletion of files in unexpected locations on the server, particularly within the GeoServer installation directory or temporary directories.
- Web server logs anomalies: Presence of specially crafted, malformed, or unusually long OGC requests targeting WFS GetFeature, WMS GetMap, WMS GetFeatureInfo, WMS GetLegendGraphic, WFS GetPropertyValue, or WPS Execute endpoints.
- Increased resource utilization: Sudden spikes in CPU or memory usage associated with the GeoServer process, indicating unauthorized code execution or resource-intensive tasks.
9. Which threat actors are known to exploit this vulnerability?
The CVE data states that "Active exploits have been published to exploit the vulnerability." While no specific threat actor groups are named, the availability of public exploits indicates that a wide range of opportunistic and targeted threat actors, from individual researchers to advanced persistent threat (APT) groups, could potentially leverage this vulnerability.
10. What public intelligence references and advisories exist?
The primary public intelligence reference is CVE-2024-36401 itself. Additionally, users should refer to the official GeoServer project's security advisories and release notes for versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, which detail the patch for this vulnerability.
11. What is the risk assessment and urgency level?
The risk level for CVE-2024-36401 is Critical, evidenced by its CVSS score of 9.8. The urgency level is immediate. This is due to several critical factors:
- Remote Code Execution (RCE): Allows unauthenticated attackers to execute arbitrary code.
- Unauthenticated Access: No prior authentication is required for exploitation.
- Widespread Impact: Affects all GeoServer instances due to a flaw in how simple feature types are handled.
- Public Exploits: Active exploits have been published, increasing the likelihood of attacks.
Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CREATE FREE ACCOUNTCVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.