Skip to main content
kcheung
Staff
Staff
September 26, 2024

FortiGuard Outbreak Alert: GeoServer RCE Attack

  • September 26, 2024
  • 0 replies
  • 413 views
Description

GeoServer is an open-source server written in Java which allow users to process geospatial data.

 

GeoServer has a vulnerability (CVE-2024-36401) where unauthenticated users could send specially crafted inputs to achieve remote code execution on the server.

 

The following versions of GeoServer is affected by CVE-2024-36401:

  • < 2.23.6
  • ≥ 2.24.0, < 2.24.4
  • ≥ 2.25.0, < 2.25.2
CVE ID

CVE-2024-36401 (https://nvd.nist.gov/vuln/detail/CVE-2024-36401)

NDR Cloud Detection Rule

FortiNDR Cloud v2024.8.1+

Detection Rule Name

Category

Primary MITRE ID

FortiGuard Outbreak Alert: GeoServer GeoTools Remote Code Execution - CVE-2024-36401

Attack: Exploitation

T1190 -  Exploit Public-Facing Application

Playbook

N/A

Threat Hunting

FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for “GeoServer RCE Attack” related activities  
IOC source: https://www.fortiguard.com/outbreak-ioc?tag=GeoServer%20RCE

All IOCs listed above have been added to Threat Intelligence Intel
Suricata Coverage

Customers can create custom investigation/detections using the Suricata signatures below:

2055805 -> ET WEB_SPECIFIC_APPS Geoserver Unsafe jxpath Evaluation RCE Attempt M1 (CVE-2024-36401)

2055808 -> ET WEB_SPECIFIC_APPS Geoserver Unsafe jxpath Evaluation RCE Attempt M2 (CVE-2024-36401)

2055809 -> ET WEB_SPECIFIC_APPS Geoserver Unsafe jxpath Evaluation RCE Attempt M3 (CVE-2024-36401)

2055810 -> ET WEB_SPECIFIC_APPS Geoserver Unsafe jxpath Evaluation RCE Attempt M4 (CVE-2024-36401)

2055811 -> ET WEB_SPECIFIC_APPS Geoserver Unsafe jxpath Evaluation RCE Attempt M5 (CVE-2024-36401)

Other Fortinet Products

For more details regarding mitigating the vulnerability by utilizing Fortinet products, please refer to
https://www.fortiguard.com/outbreak-alert/geoserver-rce