OSGeo — JAI-EXT — OSGeo GeoServer JAI-EXT contains a code injection vulnerability that, when programs use jt-jiffle and allow Jiffle script to be provided via network request, could allow remote code execution.
Details
EPSS Score
ⓘ
98.74%
99.9th percentile
Confidence
100%
CISA KEV
Date Added
Jun 26, 2024
Patch Due
Jul 17, 2024
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.