Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-35042

GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. NOTE: the vendor states that they are unable to reproduce this in any version.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.311
EPSS Ranking 96.5%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-35042


Contact Us

Shodan ® - All rights reserved