Description
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g628-r368-6vh7 | GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection |
References
History
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue. | |
| Title | GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection | |
| Weaknesses | CWE-502 CWE-74 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-18T15:57:10.555Z
Reserved: 2025-02-26T18:11:52.306Z
Link: CVE-2025-27511
Updated: 2026-06-18T15:57:06.841Z
No data.
No data.
OpenCVE Enrichment
No data.
Github GHSA