GeoServer administrators should urgently update affected systems after researchers disclosed an unauthenticated SQL injection flaw in the jsonArrayContains filter function. The issue can allow attackers to manipulate database queries via publicly accessible OGC WMS and WFS services and, under dangerous PostgreSQL privilege configurations, potentially execute commands on the database host. Security researcher @q1uf3ng publicly highlighted […]
Read the original article: