Skip to main content
Aggregate CSO Online 网络安全 15 Aug 2026 - 05:01

Attackers target zero-day vulnerability in geospatial data platform GeoServer

RSS 官方收录 · 可信分层展示

关键摘要

Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing geospatial data.…

  • The software is widely used by organizations in many industries, inclu…
  • A bug bounty hunter shared the vulnerability Wednesday on X as a zero …
  • According to his post, the jsonArrayContains function contains a vulne…

摘要引擎:抽取

正文提要

Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing geospatial data.

The software is widely used by organizations in many industries, including the government, defense, science, education, engineering and technology sectors, and has been targeted by hackers in the past.

A bug bounty hunter shared the vulnerability Wednesday on X as a zero day. According to his post, the jsonArrayContains function contains a vulnerability that allows unauthenticated users to inject SQL commands into the database.

If the database runs with administrator permissions on Microsoft SQL Server, the account also has the ability to execute commands on the system, so the SQL injection becomes a remote code execution vector. Another user confirmed on X that they were able to reproduce the flaw in a non-default configuration.

“Within hours of public disclosure, we began observing exploitation attempts and have since recorded hundreds of attempts originating from a small number of source IP addresses,” researchers from security firm watchTowr told CSO via email on Thursday. “Yet another example of how quickly attackers move once a vulnerability enters the public domain.”

So far, the researchers haven’t seen any malicious payloads or commands being sent, and the attempts look more like probes to identify vulnerable GeoServer instances. However, this is likely to change; GeoServer has a history of being exploited, since its users are usually seen as high value targets.

Until a patch becomes available, organizations who run GeoServer should identify their internet exposed instances and restrict public access to them. They should also check the logs for any signs that exploitation has already occurred.

打开官方原文 站点原文页 可信分区 本信源更多 今日简报 分享图 RSS 稍后再看列表