← Back to CVE List

CVE-2023-35042

Published: 2023-06-12T15:15Z
Last Modified: 2024-11-21T08:07Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. NOTE: the vendor states that they are unable to reproduce this in any version. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt