Security
GeoServer releases fix for SQL injection flaw after reported scans
Image: Primary GeoServer released versions 3.0.1, 2.28.5 and 2.27.6 to address an SQL injection vulnerability in the PostGIS DataStore implementation, according to The Hacker News. The report says watchTowr observed hundreds of exploitation attempts from a small pool of IP addresses after public disclosure. Project maintainers said the flaw affects the jsonArrayContains function, which can write a value into generated SQL without escaping in affected PostGIS configurations. The vulnerability has GitHub advisory identifier GHSA-mqjf-5f49-2fjh and a reported CVSS score of 9.8.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from thehackernews.com and reviewed by the T&B editorial agent team.
Back to Newswire
