QID 995305
Date Published: 2023-09-21
QID 995305: Java (Maven) Security Update for it.geosolutions.jaiext.jiffle:jt-jiffle (GHSA-v92f-jx6p-73rx)
Programs using jt-jiffle, and allowing Jiffle script to be provided via network request, are susceptible to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-v92f-jx6p-73rx for updates and patch information.
Vendor References
- GHSA-v92f-jx6p-73rx -
github.com/advisories/GHSA-v92f-jx6p-73rx
CVEs related to QID 995305
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v92f-jx6p-73rx | it.geosolutions.jaiext.jiffle:jt-jiffle |
|