## Summary Administrator can perform JNDI attack through specially crafted DB2 jdbc url leading to Remote Code Execution (RCE). ## Impact If GeoServer has DB2 extension installed, this vulnerability can lead to executing arbitrary code. ## Details Authenticated users can access Vector Data Sources page to creating a new data store through db2 jdbc connection, performing JNDI attack due to unrestricted connection parameters, and then achieve RCE with deserialization of untrusted data. ### Remediation This issue has been fixed in this release: https://github.com/geoserver/geoserver/releases/tag/2.27.0. ## References * https://osgeo-org.atlassian.net/browse/GEOT-7725 * https://nvd.nist.gov/vuln/detail/cve-2023-27867
Update org.geoserver.extension:gs-db2 to 2.27.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanGeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection affects org.geoserver.extension:gs-db2 (maven). Severity is high. ## Summary Administrator can perform JNDI attack through specially crafted DB2 jdbc url leading to Remote Code Execution (RCE). ## Impact If GeoServer has DB2 extension installed, this vulnerability can lead to executing arbitrary code. ## Details Authenticated users can access Vector Data Sources page to creating a new data store through db2 jdbc connection, performing JNDI attack due to unrestricted connection parameters, and then achieve RCE with deserialization of untrusted data. ### Remediation This issue has been fixed in this release: https://github.com/geoserver/geoserver/releases/tag/2.27.0. ## References * https://osgeo-org.atlassian.net/browse/GEOT-7725 * https://nvd.nist.gov/vuln/detail/cve-2023-27867
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
## Summary Administrator can perform JNDI attack through specially crafted DB2 jdbc url leading to Remote Code Execution (RCE). ## Impact If GeoServer has DB2 extension installed, this vulnerability can lead to executing arbitrary code. ## Details Authenticated users can access Vector Data Sources page to creating a new data store through db2 jdbc connection, performing JNDI attack due to unrestricted connection parameters, and then achieve RCE with deserialization of untrusted data. ### Remediation This issue has been fixed in this release: https://github.com/geoserver/geoserver/releases/tag/2.27.0. ## References * https://osgeo-org.atlassian.net/browse/GEOT-7725 * https://nvd.nist.gov/vuln/detail/cve-2023-27867
Update org.geoserver.extension:gs-db2 to 2.27.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanGeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection affects org.geoserver.extension:gs-db2 (maven). Severity is high. ## Summary Administrator can perform JNDI attack through specially crafted DB2 jdbc url leading to Remote Code Execution (RCE). ## Impact If GeoServer has DB2 extension installed, this vulnerability can lead to executing arbitrary code. ## Details Authenticated users can access Vector Data Sources page to creating a new data store through db2 jdbc connection, performing JNDI attack due to unrestricted connection parameters, and then achieve RCE with deserialization of untrusted data. ### Remediation This issue has been fixed in this release: https://github.com/geoserver/geoserver/releases/tag/2.27.0. ## References * https://osgeo-org.atlassian.net/browse/GEOT-7725 * https://nvd.nist.gov/vuln/detail/cve-2023-27867
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
| org.geoserver.extension:gs-db2maven | <2.27.0 | 2.27.0 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| org.geoserver.extension:gs-db2maven | <2.27.0 | 2.27.0 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard