cve entity

CVE-2022-24816

1 source-linked records in the current knowledge graph.

high

CVE-2022-24816: OSGeo GeoServer JAI-EXT Code Injection Vulnerability

OSGeo GeoServer JAI-EXT contains a code injection vulnerability that, when programs use jt-jiffle and allow Jiffle script to be provided via network request, could allow remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2022-24816EPSS 98.7%JAI-EXTOSGeo
CISA KEV ↗ · unattributed attribution