References https://github.com/vulhub/vulhub/blob/master/geoserver/CVE-2024-36401/README.zh-cn.md https://www.secrss.com/articles/67710 https://chinese.opswat.com/blog/cve-2024-36401-in-open-source-geoserver-exposes-systems-to-remote-code-execution https://y4tacker.github.io/2024/07/03/year/2024/7/%E6%B5%85%E6%9E%90GeoServer-property-%E8%A1%A8%E8%BE%BE%E5%BC%8F%E6%B3%A8%E5%85%A5%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C-CVE-2024-36401/ https://www.cnblogs.com/x3cc/p/19081102 https://cloud.tencent.com/developer/article/2437213 https://vulnerability.circl.lu/vuln/CVE-2024-36401 https://yzddmr6.com/posts/geoserver-memoryshell/ http://www.bmth666.cn/2025/04/07/CVE-2024-36401-GeoServer-RCE%E5%AE%9E%E6%88%98%E5%88%A9%E7%94%A8/index.html https://avd.aliyun.com/detail?id=AVD-2024-36401 https://get-shell.com/4040.html https://blog.csdn.net/qq_44159028/article/details/143204231 https://cve.imfht.com/detail/CVE-2024-36401 https://wh0am1i.com/2024/07/30/CVE-2024-36401-GeoServer-RCE/index.html https://github.com/amoy6228/CVE-2024-36401_Geoserver_RCE_POC https://geoserver.org/vulnerability/2024/09/12/cve-2024-36401.html https://nvd.nist.gov/vuln/detail/cve-2024-36401 https://www.keysight.com/blogs/en/tech/nwvs/2024/09/03/cve-2024-36401-rce-in-geoserver https://www.tenable.com/plugins/nessus/204972 https://github.com/Chocapikk/CVE-2024-36401 https://cert.europa.eu/publications/security-advisories/2024-068/ https://www.fortinet.com/blog/threat-research/threat-actors-exploit-geoserver-vulnerability-cve-2024-36401 https://www.sonicwall.com/blog/geoserver-rce-vulnerability-cve-2024-36401-being-exploited-in-the-wild https://geoserver.org/announcements/vulnerability/2024/06/18/geoserver-2-25-2-released.html https://www.ionix.io/threat-center/cve-2024-36401/ https://www.rapid7.com/db/vulnerabilities/geotools-complex-cve-2024-36401/ https://community.fortinet.com/fortindrcloud-59/fortiguard-outbreak-alert-geoserver-rce-attack-183258 https://www.broadcom.com/202407017-cve-2024-36401-vulnerability-in-osgeo-geoserver-geotools https://nsfocusglobal.com/remote-code-execution-vulnerability-between-geoserver-and-geotools-cve-2024-36401-cve-2024-36404-notification/ https://ethicalhacking.uk/cve-2024-36401-geoserver-and-geotools-xpath-injection-via-commons-jxpath/ https://www.youtube.com/watch?v=b_tdXutN3XQ https://www.bitsight.com/blog/geoserver-cve-2024-36401-tailoring-public-poc-enable-high-confidence-detection https://www.acunetix.com/vulnerabilities/web/geoserver-rce-cve-2024-36401/ https://hackviser.com/labs/common-vulnerabilities/cve-2024-36401 https://thehackernews.com/2024/09/geoserver-vulnerability-targeted-by.html https://feedly.com/cve/CVE-2024-36401 https://github.com/jakabakos/CVE-2024-36401-GeoServer-RCE https://medium.com/@tvvzvpb186/critical-geoserver-rce-vulnerability-cve-2024-36401-no-auth-needed-2fcb98a06418 https://socprime.com/blog/latest-threats/detect-attack-using-cve-2024-36401-aa25-266a-cisa-alert/ https://github.com/Mr-xn/CVE-2024-36401 https://www.cnvd.org.cn/flaw/show/CNVD-2024-30085 https://github.com/vulhub/vulhub/blob/master/geoserver/CVE-2024-36401/README.md https://www.juniper.net/us/en/threatlabs/ips-signatures/detail.HTTP:CTS:GEOSERVER-RCE.html https://www.youtube.com/watch?v=jNj7bRbO1ww https://rivers.chaitin.cn/vuldb/997c285a-8645-4bb3-b6ca-4b0e8ce66dbd https://www.hnitns.com/index.php?id=258 http://wlaq.njupt.edu.cn/2024/0711/c14800a267735/page.htm https://starmap.dbappsecurity.com.cn/info/5640 https://www.seczone.cn/news/453.html https://it.shanghaitech.edu.cn/aqgg_8406/list4.htm
Related VulnerabilitiesPoCCVE-2026-76904: GeoServer jsonArrayContains CQL Filter - SQL InjectionPoCgeoserver-jsonarraycontains-sqli: GeoServer jsonArrayContains CQL Filter - SQL InjectionGeoServer jsonArrayContains SQL注入漏洞GeoServer /geoserver/wms 服务器端请求伪造漏洞(CVE-2023-43795)GeoServer /geoserver/topp/wfs 代码执行漏洞PoCCVE-2025-58360: GeoServer - XML External Entity InjectionGeoServer /geoserver/wms GetMap XML 外部实体注入漏洞(CVE-2025-58360)GeoServer GetMap XML外部实体注入漏洞GeoServer GetMap 未授权XXE注入漏洞(CVE-2025-58360)GeoServer 未授权 XML外部实体注入(XXE)漏洞PoCCVE-2021-40822: Geoserver - Server-Side Request Forgery