CVE-2022-24816

Confirmed PUBLISHED

Improper Control of Generation of Code in jai-ext

geosolutions-it · jai-ext
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
10.0 Critical EPSS 98.7%

At a Glance

JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compile Jiffle scripts from the final application, by removing janino-x.y.z.jar from the classpath.

windows cisa nuclei_scanner nessus_scanner java
CVE Published
Apr 13, 2022
Exploitation Reported
Jun 26, 2024
CVSS
10.0 Critical
EPSS
98.7%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
geosolutionsgroup
jai-ext

0 to < 1.1.22

Affected
geosolutions-it
jai-ext

< 1.1.22

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.