Attackers Probe GeoServer Zero-Day in Hundreds of Attempts as Unpatched SQL Flaw Risks RCE
Updated
Updated · The Hacker News · Aug 14
Attackers Probe GeoServer Zero-Day in Hundreds of Attempts as Unpatched SQL Flaw Risks RCE
3 articles · Updated · The Hacker News · Aug 14
Summary
Hundreds of exploitation attempts have hit the newly disclosed GeoServer zero-day, with watchTowr saying attackers began probing internet-exposed systems within hours of the Aug. 12 public disclosure.
The flaw is an unpatched SQL injection bug in GeoServer's jsonArrayContains function that can enable remote code execution, especially under certain configurations and on system administrator databases.
A small pool of IP addresses is currently triggering errors and reconnaissance rather than full follow-on exploitation, but researchers warned that pattern is unlikely to last.
Organizations running GeoServer are being urged to identify exposed instances, restrict public access and monitor for a vendor fix; the bug still has no CVE identifier.
GeoServer has been exploited at scale before, including the 2024 GeoTools flaw CVE-2024-36401, a 9.8-severity bug used to build DDoS, cryptomining and proxy botnets.