Sploitus

CVE-2024-36401

45 known exploits for CVE-2024-36401

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a default GeoServer installation due to unsafely evaluating property names as XPath expressions. The GeoTools library API that GeoServer calls evaluates property/attribute names for feature types in a way that unsafely passes them to the commons-jxpath library which can execute arbitrary code when evaluating XPath expressions. This XPath evaluation is intended to be used only by complex feature types (i.e., Application Schema data stores) but is incorrectly being applied to simple feature types as well which makes this vulnerability apply to **ALL** GeoServer instances. No public PoC is provided but this vulnerability has been confirmed to be exploitable through WFS GetFeature, WFS GetPropertyValue, WMS GetMap, WMS GetFeatureInfo, WMS GetLegendGraphic and WPS Execute requests. This vulnerability can lead to executing arbitrary code. Versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2 contain a patch for the issue. A workaround exists by removing the `gt-complex-x.y.jar` file from the GeoServer where `x.y` is the GeoTools version (e.g., `gt-complex-31.1.jar` if running GeoServer 2.25.1). This will remove the vulnerable code from GeoServer but may break some GeoServer functionality or prevent GeoServer from deploying if the gt-complex module is needed.

Affected products
Geoserver
Geoserver
< 2.22.6, 2.23.6, 2.24.4, 2.25.2
Geotools
< 29.6, 30.4, 31.2, 30.0, 31.0
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
99.8% (100th percentile)
Weakness
CWE-94, CWE-95
NVD status
Analyzed
Published
2024-07-01
CVE-2024-36401 at NVD
Authoritative description, scoring and affected products

45 known exploits for CVE-2024-36401

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2024-36401
2026-08-29 KitPloitKITPLOIT
GeoServerExploit
2026-08-29 KitPloitKITPLOIT
geoserver-
2026-08-29 KitPloitKITPLOIT
cve-2024-36401-geoserver-rce
2026-08-28 KitPloitKITPLOIT
CVE-2024-36401
2026-08-28 KitPloitKITPLOIT
CVE-2024-36401-poc
2026-08-28 KitPloitKITPLOIT
CVE-2024-36401-PoC
2026-08-28 KitPloitKITPLOIT
CVE-2024-36401
2026-08-28 KitPloitKITPLOIT
CVE-2024-36401-PoC
2026-08-28 KitPloitKITPLOIT
GeoServer-CVE-2024-36401
2026-08-27 KitPloitKITPLOIT
CVE-2024-36401-MASS
2026-08-27 KitPloitKITPLOIT
GeoServer-Tools-CVE-2024-36401
2026-08-27 KitPloitKITPLOIT
CVE-2024-36401
2026-08-26 KitPloitKITPLOIT
CVE-2024-36401
2026-08-26 KitPloitKITPLOIT
CVE-2024-36401
2026-08-26 KitPloitKITPLOIT
CVE-2024-36401-GeoServer-RCE
2026-08-26 KitPloitKITPLOIT
CVE-2024-36401
2026-08-26 KitPloitKITPLOIT
CVE-2024-36401
2026-08-26 KitPloitKITPLOIT
CVE-2024-36401-WoodpeckerPlugin
2026-08-25 KitPloitKITPLOIT
CVE-2024-36401_Geoserver_RCE_POC
2026-08-25 KitPloitKITPLOIT
CVE-Web-Framework
2026-08-13 chengbochuan3GITHUB
ghost-bits-toolkit
2026-06-19 v1c0mmrtGITHUB
Exploit for Eval Injection in Geoserver
2026-06-03 DanieleGiovanardi2408GITHUB
Exploit for Code Injection in Geoserver
2026-05-30 Delt-AGITHUB
Exploit for Code Injection in Geoserver
2025-10-04 URJACK2025GITHUB
Exploit for Code Injection in Geoserver
2025-04-30 amoy6228GITHUB
Exploit for Code Injection in Geoserver
2024-11-27 0x0d3adGITHUB
Exploit for Code Injection in Geoserver
2024-11-22 XiaomingXGITHUB
Exploit for Code Injection in Geoserver
2024-11-22 thestar0GITHUB
Exploit for Code Injection in Geoserver
2024-10-14 kkhackz0013GITHUB
Exploit for Code Injection in Geoserver
2024-10-05 netuseradministratorGITHUB
Exploit for Code Injection in Geoserver
2024-09-13 daniellowrieGITHUB
Exploit for Code Injection in Geoserver
2024-08-27 justin-pGITHUB
Exploit for Code Injection in Geoserver
2024-08-01 yisas93GITHUB
Exploit for Code Injection in Geoserver
2024-07-30 ChocapikkGITHUB
Exploit for Code Injection in Geoserver
2024-07-17 ahisecGITHUB
Geoserver Unauthenticated Remote Code Execution Exploit
2024-07-16 metasploitZDTRuby
Geoserver Unauthenticated Remote Code Execution
2024-07-15 jheysel-r7, h00die-gr3y, Steve Ikeoka, metasploit.comPACKETSTORMRuby
Exploit for Code Injection in Geoserver
2024-07-12 jakabakosGITHUB
Exploit for Code Injection in Geoserver
2024-07-06 Mr-xnGITHUB
Exploit for Code Injection in Geoserver
2024-07-05 NiuwooGITHUB
Exploit for Code Injection in Geoserver
2024-07-05 RevoltSecuritiesGITHUB
Exploit for Code Injection in Geoserver
2024-07-04 bigb0xGITHUB
Geoserver unauthenticated Remote Code Execution
2024-07-01 h00die-gr3y <h00die.gr3y@gmail.com>, jheysel-r7, Steve Ikeoka, Valentin Lobstein a.k.a chocapikkMETASPLOITRuby
Exploit for Command Injection in Tp-Link Archer_Ax21_Firmware
2024-05-08 ahisecGITHUB