CVE-2022-24846 is a critical vulnerability affecting GeoWebCache, a Java-based tile caching server, and its integration within GeoServer. It allows for unchecked JNDI lookups within the disk quota mechanism, leading to class deserialization and arbitrary code execution. With a CVSS score of 7.2 (High), this vulnerability can be exploited remotely by an authenticated attacker with administrative privileges, resulting in full compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.19.3CPE matchmatch criteria | cpe:2.3:a:geoserver:geowebcache:*:*:*:*:*:*:*:* | ||
>= 1.20.0, < 1.20.2CPE matchmatch criteria | cpe:2.3:a:geoserver:geowebcache:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.