Programs run on GeoServer before 1.2.2 which use jt-jiffle and allow Jiffle script to be provided via network request are susceptible to remote code execution. The Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects downstream GeoServer 1.1.22.
id: CVE-2022-24816
info:
name: GeoServer <1.2.2 - Remote Code Execution
author: mukundbhuva
s
...