Description | This article describes GeoServer RCE Attack vulnerability detection with FortiDevSec. CVE-2024-36401 is a critical vulnerability affecting GeoServer versions earlier than 2.23.6, 2.24.4, and 2.25.2. This vulnerability allows unauthenticated users to execute arbitrary code on a default GeoServer installation by sending specially crafted input. The issue stems from the unsafe handling of property names as XPath expressions due to a flaw in the GeoTools library API, which GeoServer relies on. |
Scope | FortiDevSec SCA scanner updated in version 24.2 |
Solution |
Detection against these vulnerabilities is empowered by the FortiDevSec Software Composition Analysis (SCA) scanner. A step-by-step guide on how to scan an application is available in the user-guide For more details regarding mitigating the vulnerability by utilizing Fortinet products, please refer to https://www.fortiguard.com/outbreak-alert/geoserver-rce |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.