SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  GeoServer JAI-EXT Remote Code Execution

Category: WEB-ATTACKS      

JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project.


Relevant Information