Netskope Threat Labs

SERVER-WEBAPP GeoServer WMS remote code execution attempt

IPS-NPA

2 SIDs: 63762, 63763

Detects an attempt to exploit CVE-2024-36401, a remote code execution flaw that can run code on the server in GeoServer WMS. The flaw saw mass exploitation against internet-facing GeoServer instances.