Summary
GeoServer is facing an unpatched zero-day SQL injection vulnerability in its jsonArrayContains function that allows unauthenticated attackers to achieve remote code execution. Security researchers have already observed hundreds of exploitation probes targeting internet-exposed instances across government and defense sectors.
Take Action:
If you run GeoServer, isolate it from the public internet immediately and put it behind a VPN. Attackers are already scanning for a flaw that doesn't have a patch. Isolation is your only real defense.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)