CVE-2023-25157 is a critical SQL injection vulnerability (CWE-89) affecting GeoServer, an open-source Java-based geospatial data server. This flaw, stemming from improper handling of OGC Filter expressions and CQL within WFS, WMS, and WCS protocols, allows unauthenticated attackers to execute arbitrary SQL commands. With a CVSS score of 9.8 (Critical), it poses a severe risk of complete compromise (confidentiality, integrity, availability). While not yet observed in the KEV catalog, exploit intelligence indicates public Nuclei templates exist, and its high EPSS and FAUCET scores, along with community discussion, suggest significant attention and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.18.7CPE matchmatch criteria | cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:* | ||
>= 2.19.0, < 2.19.7CPE matchmatch criteria | cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:* | ||
>= 2.20.0, < 2.20.7CPE matchmatch criteria | cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:* | ||
>= 2.21.0, < 2.21.4CPE matchmatch criteria | cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:* | ||
>= 2.22.0, < 2.22.2CPE matchmatch criteria | cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.