CVE-2022-24816
OSGeo GeoServer JAI-EXT Code Injection Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 10
- EPSS
- 98.7% 백분위 99.9% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2024.07.17
- 공개일
- 2022.04.14
CISA KEV에 등록된 실제 악용 확인 취약점
JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compile Jiffle scripts from the final application, by removing janino-x.y.z.jar from the classpath.
공급사 OSGeo
제품 JAI-EXT
영향 버전 < 1.1.22, 0
수정 버전 1.1.22
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
조치 기한: 2024.07.17CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE CWE-94
KEV 등록일 2024.06.26
랜섬웨어 캠페인 사용 미확인
CISA 비고 This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. The patched JAI-EXT is version 1.1.22: https://github.com/geosolutions-it/jai-ext/releases/tag/1.1.22, https://github.com/geosolutions-it/jai-ext/security/advisories/GHSA-v92f-jx6p-73rx; https://nvd.nist.gov/vuln/detail/CVE-2022-24816
EPSS 데이터 기준일 2026.06.27