CVE-2024-36404 is a critical Remote Code Execution (RCE) vulnerability in GeoTools, an open-source Java library, affecting versions prior to 31.2, 30.4, and 29.6. It allows unauthenticated attackers to execute arbitrary code by exploiting user-supplied XPath expressions. With a CVSS score of 9.8 (CRITICAL) and an EPSS score of 0.90747, this vulnerability poses a significant risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While no Metasploit or ExploitDB modules exist, Nuclei templates are available, and there is evidence of active exploitation and media coverage, indicating a high likelihood of real-world attacks. Organizations are advised to update affected GeoTools versions immediately or implement provided workarounds.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Geotools | Geotools | < 29.6, >= 30.0, < 30.4, >= 31.0, < 31.2CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.