Description
GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. NOTE: the vendor states that they are unable to reproduce this in any version.
Remediation
References
Related Vulnerabilities
WordPress Plugin BA Book Everything Cross-Site Scripting (1.3.24)
SharePoint CVE-2021-38651 Vulnerability (CVE-2021-38651)
WordPress Plugin Photospace Responsive Gallery Unspecified Vulnerability (1.1.7)
MySQL CVE-2022-21355 Vulnerability (CVE-2022-21355)
Oracle Application Server Resource Management Errors Vulnerability (CVE-2007-2120)