CVE-2023-25158 is an SQL injection vulnerability in GeoTools gt-jdbc OGC Filter parsing, encoding, and execution for JDBCDataStore implementations. Crafted OGC Filter expressions can reach SQL-generation paths for relational datastores. Affected filter and function handling includes PropertyIsLike, strEndsWith, strStartsWith, FeatureId, jsonArrayContains, and DWithin, subject to datastore-specific conditions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This is a Docker Compose-based local training lab and operational PowerShell proof-of-concept suite for GeoServer/GeoTools OGC Filter SQL injection vulnerabilities CVE-2023-25157 and CVE-2023-25158. The main exploit automation is attack-chain.ps1, supported by shared HTTP helpers in lab-common.ps1 and shorter differential PoCs for each CVE. It sends unauthenticated WFS 1.1.0 GetCapabilities, DescribeFeatureType, and GetFeature requests to the exposed gateway, then exercises CQL_FILTER function and text FeatureId injection paths. Evidence files preserve the generated request URLs and responses from a successful run. The lab builds vulnerable GeoServer 2.22.0/GeoTools 28.0, patched GeoServer 2.22.2/GeoTools 28.2, two mitigation configurations, and an optional deliberately over-privileged worst-case configuration. OpenResty exposes only 127.0.0.1:8889 and maps distinct paths to each profile; GeoServer and PostGIS are segregated into Docker networks and are not host-published. The realistic route strips SQL errors but does not prevent the demonstrated result-count boolean oracle. The repository additionally contains SQL database seeding and privilege models, a non-JDBC shapefile negative control, setup/validation scripts, gateway configuration, a Vietnamese exploit guide/report, and report-generation assets. The standard attack chain is constrained to lab canaries and read-only data extraction: it demonstrates that least privilege blocks access to internal_assets, whereas the geoserver_impact role permits canary disclosure. The optional worst-case script is separate and reads only the mounted /lab/flag.txt lab canary.
This repository is a small standalone Python proof-of-concept exploit for an unauthenticated GeoServer/GeoTools SQL injection that is claimed to lead to RCE through PostgreSQL COPY TO PROGRAM. The repository contains four files: a README with vulnerability background, exploitation examples, and lab instructions; a docker-compose.yml that provisions a GeoServer plus PostGIS/PostgreSQL test environment; a .gitignore; and the main exploit script exploit.py. The exploit logic is entirely in exploit.py. The build_payload() function takes a target column and operator-supplied OS command, escapes single quotes for SQL, wraps the command in COPY (SELECT 1) TO PROGRAM '<command>', then embeds that SQL into a malicious CQL_FILTER value. The injected filter is designed to terminate the intended jsonArrayContains expression and append arbitrary SQL. The exploit_rce() function sends an HTTP GET request with WFS parameters (service=WFS, version=2.0.0, request=GetFeature, typeNames=<workspace>:<layer>, outputFormat=application/json, and the malicious CQL_FILTER) to the constructed endpoint <base_url>/<workspace>/ows. It treats HTTP 200, 400, or 500 as possible success indicators, with 400 explicitly noted as an expected injection signal. Operationally, this is an RCE enabler rather than a post-exploitation framework: the operator supplies the exact command to run, such as creating a file or launching a reverse shell. There is no automated callback handling, shell staging, persistence, or target discovery. The included docker-compose lab shows the intended target profile: GeoServer connected to PostgreSQL/PostGIS, with example REST API calls to create a datastore and publish a layer. Overall, the repository’s purpose is to demonstrate and validate SQL injection to command execution against a vulnerable GeoServer deployment backed by PostgreSQL.
This repository is a vulnerable lab and proof-of-concept documentation set for GeoServer/GeoTools SQL injection vulnerabilities CVE-2023-25157 and CVE-2023-25158. It is not an automated exploit tool; instead, it provides a reproducible Docker environment plus detailed exploitation guidance showing how malicious WFS filter input is translated into unsafe SQL against PostgreSQL/PostGIS. Repository structure: README.md gives the overview and startup instructions; REPORT.md is the main technical write-up describing four tested attack vectors and sample HTTP requests/SQL behavior; docker-compose.yml launches a two-container lab (GeoServer 2.22.1 and PostGIS/PostgreSQL 13-3.1); init.sql creates sample spatial tables and seed data; startup.sh auto-configures GeoServer through its REST API, creating a workspace, vulnerable PostGIS datastore, and two published feature types. Main exploit capabilities: the PoC demonstrates unauthenticated or weakly protected web exploitation over GeoServer WFS endpoints using crafted CQL_FILTER or OGC XML Filter input. The documented vectors include strStartsWith, strEndsWith, PropertyIsLike, and FeatureId-based injection. The goal is error-based SQL injection: attacker-controlled input breaks out of generated SQL string context, appends SQL such as a CAST(version()) expression, and causes PostgreSQL to return an error containing backend version information. This proves arbitrary SQL expression injection in the query path, though the repository stops at information disclosure and does not include automation, shells, or persistence payloads. Notable targeting details: the lab intentionally enables vulnerable datastore settings in startup.sh, especially 'encode functions=true' and 'preparedStatements=false', and exposes primary keys. The FeatureId vector specifically depends on a string primary key table (example_str). The exploit surface is GeoServer's HTTP/WFS interface, while the backend target is PostgreSQL/PostGIS. Overall maturity is best classified as POC because the repository is a lab and report with manual payloads rather than a weaponized exploit implementation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Critical pre-authentication SQL injection vulnerability in the gt-jdbc-postgis component of GeoTools, exploitable via GeoServer OGC endpoints using vulnerable PostGIS datastores; in some configurations it can lead to arbitrary code execution. The content states this issue is a regression that reintroduces logic previously tracked as CVE-2023-25158.
A prior critical SQL injection vulnerability in GeoTools/GeoServer referenced as the regression source for the newly discussed flaw.
A SQL injection vulnerability in GeoServer's JDBCDataStore component, specifically when the 'Encode Functions' option is enabled (non-default). Allows attackers to inject SQL via crafted CQL payloads, leading to potential data compromise.
A SQL injection vulnerability in GeoTools, which can be exploited via OGC filter injection in GeoServer, allowing attackers to execute arbitrary SQL queries against the backend database.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.