CVE-2023-35042 describes a critical remote code execution (RCE) vulnerability in GeoServer 2, specifically allowing attackers to execute arbitrary code via wps:LiteralData within a wps:Execute request in certain configurations. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While the vendor claims inability to reproduce it, the vulnerability was reportedly exploited in the wild in June 2023, though there is no public exploit code (Metasploit, Nuclei, ExploitDB) or significant community discussion/media coverage at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0CPE matchmatch criteria | cpe:2.3:a:geoserver:geoserver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.