PT-2022-16896 · Janino+2 · Janino+2
Aaime
+1
·
Published
2022-04-13
·
Updated
2024-09-24
·
CVE-2022-24816
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JAI-EXT versions prior to 1.2.22
GeoServer (affected versions not specified)
Description
Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. This affects the downstream GeoServer project.
Recommendations
For JAI-EXT versions prior to 1.2.22, update to version 1.2.22 to patch the vulnerability.
As a temporary workaround for users unable to upgrade, remove janino-x.y.z.jar from the classpath to negate the ability to compile Jiffle scripts from the final application.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geoserver
Jai-Ext
Janino