[Geoserver-devel] [JIRA] (GEOS-7124) Remote Code Execution with Xstream

Matthias Kaiser created an issue

GeoServer / BugGEOS-7124

Remote Code Execution with Xstream

Issue Type:

BugBug

Affects Versions:

2.7.1.1

Assignee:

Unassigned

Attachments:

geoserver.txt

Components:

REST

Created:

24/Jul/15 12:45 PM

Labels:

Security

Priority:

HighestHighest

Reporter:

Matthias Kaiser

Hello GeoServer Team,

I’d like to report to you a remote code execution vulnerability.
I found it during a penetration test for a customer this week.

The the attached requests executes" /usr/bin/xterm" on the target

The problem is that your REST implementation is using Xstream that is configured in an insecure way.

Please let me know if you have any questions.

Thank you,
Matthias

Add Comment

Add Comment

This message was sent by Atlassian JIRA (v6.5-OD-08-001#65007-sha1:1fc9846)

Atlassian logo