DEV Community

Cover image for Attackers Exploit Unpatched GeoServer Zero-Day to Run SQL Commands
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Attackers Exploit Unpatched GeoServer Zero-Day to Run SQL Commands

Summary

GeoServer is facing an unpatched zero-day SQL injection vulnerability in its jsonArrayContains function that allows unauthenticated attackers to achieve remote code execution. Security researchers have already observed hundreds of exploitation probes targeting internet-exposed instances across government and defense sectors.

Take Action:

If you run GeoServer, isolate it from the public internet immediately and put it behind a VPN. Attackers are already scanning for a flaw that doesn't have a patch. Isolation is your only real defense.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)