CVE-2023-25158 is a critical SQL Injection vulnerability affecting GeoTools, an open-source Java library for geospatial data, specifically when OGC Filters are executed with JDBCDataStore implementations. This vulnerability, rated 9.8 CVSS (Critical), allows unauthenticated remote attackers to achieve full compromise of confidentiality, integrity, and availability. While there is no known active exploitation, public exploit code, or significant community discussion, immediate patching to versions 27.4 or 28.2 is strongly recommended, or implementing partial mitigations such as disabling "encode functions" for PostGIS DataStores or enabling "prepared statements" for JDBCDataStores.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 24.7CPE matchmatch criteria | cpe:2.3:a:geotools:geotools:*:*:*:*:*:*:*:* | ||
>= 25.0, < 25.7CPE matchmatch criteria | cpe:2.3:a:geotools:geotools:*:*:*:*:*:*:*:* | ||
>= 26.0, < 26.7CPE matchmatch criteria | cpe:2.3:a:geotools:geotools:*:*:*:*:*:*:*:* | ||
>= 27.0, < 27.4CPE matchmatch criteria | cpe:2.3:a:geotools:geotools:*:*:*:*:*:*:*:* | ||
>= 28.0, < 28.2CPE matchmatch criteria | cpe:2.3:a:geotools:geotools:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.