Description
GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. NOTE: the vendor states that they are unable to reproduce this in any version.
Remediation
References
Related Vulnerabilities
Python Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-1015)
WordPress Plugin Elementor Website Builder Multiple Vulnerabilities (3.16.4)
WebLogic Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2018-10237)
WordPress Plugin Coming Soon Page & Maintenance Mode Unspecified Vulnerability (1.8.2)
WordPress Plugin ProfileGrid-User Profiles, Groups and Communities Remote Code Execution (2.8.5)