Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3pj-wh35-fq8w

Опубликовано: 05 фев. 2025
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions

Summary

Remote Code Execution (RCE) is possible if an application uses certain GeoTools functionality to evaluate XPath expressions supplied by user input.

Details

The following methods pass XPath expressions to the commons-jxpath library which can execute arbitrary code and would be a security issue if the XPath expressions are provided by user input.

  • org.geotools.appschema.util.XmlXpathUtilites.getXPathValues(NamespaceSupport, String, Document)
  • org.geotools.appschema.util.XmlXpathUtilites.countXPathNodes(NamespaceSupport, String, Document)
  • org.geotools.appschema.util.XmlXpathUtilites.getSingleXPathValue(NamespaceSupport, String, Document)
  • org.geotools.data.complex.expression.FeaturePropertyAccessorFactory.FeaturePropertyAccessor.get(Object, String, Class<T>)
  • org.geotools.data.complex.expression.FeaturePropertyAccessorFactory.FeaturePropertyAccessor.set(Object, String, Object, Class)
  • org.geotools.data.complex.expression.MapPropertyAccessorFactory.new PropertyAccessor() {...}.get(Object, String, Class<T>)
  • org.geotools.xsd.StreamingParser.StreamingParser(Configuration, InputStream, String)

PoC

The following inputs to StreamingParser will delay the response by five seconds:

new org.geotools.xsd.StreamingParser( new org.geotools.filter.v1_0.OGCConfiguration(), new java.io.ByteArrayInputStream("<Filter></Filter>".getBytes()), "java.lang.Thread.sleep(5000)") .parse();

Impact

This vulnerability can lead to executing arbitrary code.

Mitigation

GeoTools can operate with reduced functionality by removing the gt-complex jar from your application. As an example of the impact application schema datastore would not function without the ability to use XPath expressions to query complex content.

The SourceForge download page lists drop-in-replacement jars for GeoTools: 31.1, 30.3, 30.2, 29.2, 28.2, 27.5, 27.4, 26.7, 26.4, 25.2, 24.0. These jars are for download only and are not available from maven central, intended to quickly provide a fix to affected applications.

References

https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv https://osgeo-org.atlassian.net/browse/GEOT-7587 https://github.com/geotools/geotools/pull/4797 https://github.com/Warxim/CVE-2022-41852?tab=readme-ov-file#workaround-for-cve-2022-41852

Ссылки

Пакеты

Наименование

org.geotools:gt-app-schema

maven
Затронутые версииВерсия исправления

>= 30.0, < 30.4

30.4

Наименование

org.geotools:gt-complex

maven
Затронутые версииВерсия исправления

>= 30.0, < 30.4

30.4

Наименование

org.geotools.xsd:gt-xsd-core

maven
Затронутые версииВерсия исправления

>= 30.0, < 30.4

30.4

Наименование

org.geotools:gt-app-schema

maven
Затронутые версииВерсия исправления

>= 31.0, < 31.2

31.2

Наименование

org.geotools:gt-complex

maven
Затронутые версииВерсия исправления

>= 31.0, < 31.2

31.2

Наименование

org.geotools.xsd:gt-xsd-core

maven
Затронутые версииВерсия исправления

>= 31.0, < 31.2

31.2

Наименование

org.geotools:gt-app-schema

maven
Затронутые версииВерсия исправления

>= 29.0, < 29.6

29.6

Наименование

org.geotools:gt-complex

maven
Затронутые версииВерсия исправления

>= 29.0, < 29.6

29.6

Наименование

org.geotools.xsd:gt-xsd-core

maven
Затронутые версииВерсия исправления

>= 29.0, < 29.6

29.6

Наименование

org.geotools:gt-app-schema

maven
Затронутые версииВерсия исправления

< 28.6

28.6

Наименование

org.geotools:gt-complex

maven
Затронутые версииВерсия исправления

< 28.6

28.6

Наименование

org.geotools.xsd:gt-xsd-core

maven
Затронутые версииВерсия исправления

< 28.6

28.6

EPSS

Процентиль: 100%
0.90268
Критический

9.8 Critical

CVSS3

Дефекты

CWE-95

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) is possible if an application uses certain GeoTools functionality to evaluate XPath expressions supplied by user input. Versions 31.2, 30.4, and 29.6 contain a fix for this issue. As a workaround, GeoTools can operate with reduced functionality by removing the `gt-complex` jar from one's application. As an example of the impact, application schema `datastore` would not function without the ability to use XPath expressions to query complex content. Alternatively, one may utilize a drop-in replacement GeoTools jar from SourceForge for versions 31.1, 30.3, 30.2, 29.2, 28.2, 27.5, 27.4, 26.7, 26.4, 25.2, and 24.0. These jars are for download only and are not available from maven central, intended to quickly provide a fix to affected applications.

CVSS3: 9.8
fstec
больше 1 года назад

Уязвимость библиотеки GeoTools программного обеспечения для администрирования и публикации геоданных на сервере OSGeo GeoServer, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 100%
0.90268
Критический

9.8 Critical

CVSS3

Дефекты

CWE-95