PT-2022-16896 · Janino+2 · Janino+2

·

CVE-2022-24816

·

Published

2022-04-13

·

Updated

2024-09-24

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JAI-EXT versions prior to 1.2.22 GeoServer (affected versions not specified)
Description Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. This affects the downstream GeoServer project.
Recommendations For JAI-EXT versions prior to 1.2.22, update to version 1.2.22 to patch the vulnerability. As a temporary workaround for users unable to upgrade, remove janino-x.y.z.jar from the classpath to negate the ability to compile Jiffle scripts from the final application.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24816
GHSA-V92F-JX6P-73RX

Affected Products

Geoserver
Jai-Ext
Janino