CVE-2023-35042: GeoServer
Critical severity, CVSS 9.8. EPSS: 43.2% chance of exploitation in the next 30 days.
GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. NOTE: the vendor states that they are unable to reproduce this in any version.
Affected products
- GeoServer GeoServer: from 2.0.0
Published 2023-06-12. Last modified 2026-06-17.