CVE 7.2 HIGH

GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection_CVE-2025-27511

7.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue.

Basic Information

ID CVE-2025-27511
Source GitHub_M
Published Jun 18, 2026 at 14:23
Modified Jun 18, 2026 at 15:57

Affected Product

Vendor geoserver
Product org.geoserver.extension:gs-db2
Version < 2.27.0
Affected Versions geoserver org.geoserver.extension:gs-db2 < 2.27.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.