CVE-2022-24816

OSGeo GeoServer JAI-EXT Code Injection Vulnerability

Description

OSGeo GeoServer JAI-EXT contains a code injection vulnerability that, when programs use jt-jiffle and allow Jiffle script to be provided via network request, could allow remote code execution.

Severity: CRITICAL

CVSS Score: 10

Vendor: OSGeo

Product: JAI-EXT

Loading CVE details...