Information about latest alleged GeoServer security vulnerabilities
Dear Reader, In recent days, news of a new GeoServer vulnerability, CVE-2023-35042, has been released and has drawn some attention on Twitter and on some security related websites. According to NIST, the vulnerability is “undergoing analysis”. At the same time, the report has been opened without any report to the GeoServer project. The source of the report appears to be this blog post, where a security researcher reports attack attempts on a GeoServer honeypot server he set up, with an example request using the WPS protocol to perform a code injection by means of an embedded Jiffle script. In particular,...
More