← back
CVE-2023-35042observed exploitation

CVE-2023-35042

37Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendepss 43%
from disclosure to weapon
Published on NVDJun 12
VulnCheckJun 12
exploitation probability
43%top 1% of all CVEs
observed exploitation
yesVulnCheck
GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. NOTE: the vendor states that they are unable to reproduce this in any version.
Affected products
n/a · n/a