CVE-2022-24816

unknown KEV
Published 2023-09-19 · Modified 2024-06-26
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H
CVSS v2
VIR risk
1.5

Description

OSGeo GeoServer JAI-EXT contains a code injection vulnerability that, when programs use jt-jiffle and allow Jiffle script to be provided via network request, could allow remote code execution.

CISA KEV

Vendor
OSGeo
Product
JAI-EXT
Due date
2024-07-17

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. The patched JAI-EXT is version 1.1.22: https://github.com/geosolutions-it/jai-ext/releases/tag/1.1.22, https://github.com/geosolutions-it/jai-ext/security/advisories/GHSA-v92f-jx6p-73rx; https://nvd.nist.gov/vuln/detail/CVE-2022-24816

Exploits

Package impact

EcosystemPackageVulnerableFixed
java Mavenit.geosolutions.jaiext.jiffle:jt-jiffle<1.1.221.1.22
java Mavenit.geosolutions.jaiext.jiffle:jt-jiffle-language<1.1.221.1.22

References

Verify integrity in audit chain (admin only). AS-IS.