Updated
Updated · The Hacker News · Aug 14
Attackers Probe GeoServer Zero-Day in Hundreds of Attempts as Unpatched SQL Flaw Risks RCE
Updated
Updated · The Hacker News · Aug 14

Attackers Probe GeoServer Zero-Day in Hundreds of Attempts as Unpatched SQL Flaw Risks RCE

3 articles · Updated · The Hacker News · Aug 14

Summary

  • Hundreds of exploitation attempts have hit the newly disclosed GeoServer zero-day, with watchTowr saying attackers began probing internet-exposed systems within hours of the Aug. 12 public disclosure.
  • The flaw is an unpatched SQL injection bug in GeoServer's jsonArrayContains function that can enable remote code execution, especially under certain configurations and on system administrator databases.
  • A small pool of IP addresses is currently triggering errors and reconnaissance rather than full follow-on exploitation, but researchers warned that pattern is unlikely to last.
  • Organizations running GeoServer are being urged to identify exposed instances, restrict public access and monitor for a vendor fix; the bug still has no CVE identifier.
  • GeoServer has been exploited at scale before, including the 2024 GeoTools flaw CVE-2024-36401, a 9.8-severity bug used to build DDoS, cryptomining and proxy botnets.

Insights

Are critical infrastructure sectors already compromised by the unpatched GeoServer SQL injection despite only reconnaissance being reported so far?
Will the potential fixes in recent GeoServer updates be enough to stop attackers from exploiting the jsonArrayContains zero-day flaw?
How can organizations secure geospatial data if administrative endpoints remain exposed to unauthenticated SQL injection attacks?