CVE Tools

Rondo Meets Geoserver - SANS Internet Storm Center

SANS Internet Storm CenterBy SANS Internet Storm Center

PoC publicGeoServer

Our summary

A recent log entry revealed an ongoing attack targeting Geoserver through CVE-2024-36401, an X-Path expression evaluation flaw. The exploit attempts to execute arbitrary commands on vulnerable systems using the Rondo botnet. Attackers are deploying malicious shell scripts hosted remotely, leveraging multiple download methods such as wget and curl. This vulnerability allows unauthenticated attackers to run arbitrary code, making it critical for users to apply patches immediately.

Read at SANS Internet Storm Center

SANS Internet Storm Center publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store