7.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Description
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue.
Basic Information
ID
CVE-2025-27511
Source
GitHub_M
Published
Jun 18, 2026 at 14:23
Modified
Jun 18, 2026 at 15:57
Affected Product
Vendor
geoserver
Product
org.geoserver.extension:gs-db2
Version
< 2.27.0
Affected Versions
geoserver org.geoserver.extension:gs-db2 < 2.27.0