Threat actors began exploiting an unpatched GeoServer zero-day within hours of its public disclosure, targeting an SQL injection flaw in the jsonArrayContains function that can lead to remote code execution. WatchTowr recorded hundreds of probing attempts from a small number of source IPs, urging organizations to identify exposed GeoServer instances and restrict public access while waiting for a fix. #GeoServer #q1uf3ng #WatchTowr #CISA
Keypoints
- Attackers moved quickly after the GeoServer zero-day was disclosed publicly.
- The flaw is an SQL injection issue in the jsonArrayContains function.
- Under certain configurations, the bug can lead to remote code execution.
- WatchTowr observed hundreds of exploitation attempts from limited source IPs.
- Organizations using GeoServer should find exposed systems and restrict access.
Read More: https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/