CVE-2022-24816 is a critical Remote Code Execution (RCE) vulnerability affecting JAI-EXT, specifically impacting the downstream GeoServer project. It allows unauthenticated attackers to inject malicious Jiffle scripts via network requests, which are then compiled and executed. With a CVSS score of 10.0, this vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. This flaw is actively exploited in the wild, has a high EPSS score, and has garnered significant community and media attention, including a CISA warning.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.22CPE matchmatch criteria | cpe:2.3:a:geosolutionsgroup:jai-ext:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.