GHSA-59x6-g4jr-4hxc
CRITICALCVE-2023-35042GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023.
- Affected
- >= 2.20.0, < 2.20.4, >= 2.19.0, < 2.19.6, < 2.18.6
- Fixed in
- 2.20.4
- Published
- 2023-06-12
- Source
- github