CVE-2024-36404 is a remote code execution vulnerability in GeoTools, an open source Java library for geospatial data. The vulnerability exists in versions prior to 31.2, 30.4, and 29.6, and is triggered when user-supplied input is evaluated as XPath expressions by certain GeoTools functionality. This allows attackers to inject and execute arbitrary code on the affected system if the application processes untrusted XPath expressions via GeoTools.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository is a self-contained reproduction and exploit study for CVE-2024-36401, an unauthenticated GeoServer RCE caused by unsafe JXPath evaluation in GeoTools. It is not tied to a major exploit framework; the main exploit logic is implemented in `exploit/exploit.py` with a secondary curl-based PoC in `exploit/exploit.sh`. Structure: `docker/` contains two nearly identical Dockerfiles that build GeoServer 2.25.1 (vulnerable) and 2.25.2 (patched) from official SourceForge binaries; `docker-compose.yml` exposes them on localhost ports 8080 and 8081; `exploit/` contains the Python exploit/verifier, shell PoC, payload catalog, and captured proof artifacts; `run-reproduction.sh` automates build, readiness checks, exploitation of both instances, and proof collection; `report/report.md` is a detailed technical write-up. Exploit capability: the Python script first enumerates layers via WFS GetCapabilities, then sends WFS GetPropertyValue requests with attacker-controlled `valueReference` values. It uses a blind timing payload `java.lang.Thread.sleep(8000)` to detect code execution from client-side response delay, and a command-execution payload `exec(java.lang.Runtime.getRuntime(),'touch /tmp/<marker>')` to create a file inside the target container. The shell PoC demonstrates the same technique with GET and POST/XML requests and documents that POST may help bypass defenses inspecting only query strings. `payloads.md` also documents alternate vectors through WFS GetFeature and WMS GetMap using `CQL_FILTER`. Observed behavior in included logs confirms real exploitation on the vulnerable instance: the blind probe delays the response by ~8 seconds and the file `/tmp/cve3641_1780498920` is created only on the vulnerable container. On the patched instance, the same payloads are rejected with `No such attribute` errors and no file is created. Overall, this is a legitimate operational PoC/verifier for unauthenticated web/network RCE against vulnerable GeoServer deployments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.