GeoTools是GeoTools组织开源的一个地理空间数据处理框架。 GeoTools 30.5至33.6之前版本、34.0至34.5之前版本和35.0版本存在SQL注入漏洞,该漏洞源于使用PostGIS DataStore执行OGC Filters时jsonArrayContains函数未对value参数进行转义,导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoTools FilterToSqlHelper.constructEquality writes the expected argument of the jsonArrayContains CQL function RAW into the SQL string while only escaping the JSON pointer. A single quote in the value parameter breaks out of the PostgreSQL jsonb_path_exists string literal, enabling unauthenticated SQL injection. When the PostGIS backend runs with superuser privileges, the injection escalates to operating system command execution through PostgreSQL COPY TO PROGRAM. Users are advised to upgrade to either version 2.21.4, or version 2.22.2 to resolve this issue. Users unable to upgrade should enable the PostGIS DataStore preparedStatements setting and disable encode functions as a workaround. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-76904.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet