QID 995305

Date Published: 2023-09-21

QID 995305: Java (Maven) Security Update for it.geosolutions.jaiext.jiffle:jt-jiffle (GHSA-v92f-jx6p-73rx)

Programs using jt-jiffle, and allowing Jiffle script to be provided via network request, are susceptible to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Github security advisory GHSA-v92f-jx6p-73rx for updates and patch information.
    Vendor References

    CVEs related to QID 995305

    Software Advisories
    Advisory ID Software Component Link
    GHSA-v92f-jx6p-73rx it.geosolutions.jaiext.jiffle:jt-jiffle URL Logo github.com/advisories/GHSA-v92f-jx6p-73rx