Cybercriminals have begun exploiting a newly discovered zero-day vulnerability in GeoServer, just hours after it was publicly disclosed. This vulnerability, identified as an SQL injection flaw, was revealed by security researcher q1uf3ng and affects the jsonArrayContains function within GeoServer. This function is used for querying JSON array fields and is compatible with PostGIS and Oracle JDBC data stores. The vulnerability arises from inadequate sanitization of user-supplied input, leading to potential remote code execution. WatchTowr, an attack surface management company, has observed numerous exploitation attempts from a limited number of source IP addresses soon after the disclosure. This rapid response underscores the urgency with which threat actors act when such vulnerabilities are made public. Although there has been no observed follow-up activity, GeoServer's history of being exploited at scale suggests that the situation could escalate. Organizations using GeoServer, which is widely employed across various sectors including government and agriculture, are advised to take this threat seriously. With no patch available yet, it is crucial for these entities to identify exposed systems, restrict public access, and stay vigilant for updates from the vendor.
GeoServer Zero-Day Vulnerability: Immediate Exploitation Risks Highlighted
An unpatched GeoServer SQL-injection zero-day is being exploited in the wild, potentially enabling remote code execution and data theft.


