JNDI Attack Vulnerability in GeoServer DB2 DataStore Extension
CVE-2025-27511
7.2HIGH
What is CVE-2025-27511?
GeoServer's DB2 DataStore Extension prior to version 2.27.0 is susceptible to a JNDI attack via a maliciously constructed DB2 JDBC URL, which can allow an administrator to execute remote code. This vulnerability poses significant security risks, especially in environments where geospatial data is shared and edited. Users are urged to upgrade to version 2.27.0 or later to safeguard against this threat.
Affected Version(s)
org.geoserver.extension:gs-db2 < 2.27.0
