Netskope Threat Labs

SERVER-WEBAPP GeoServer WPS remote code execution attempt

IPS-NPA

2 SIDs: 63760, 63761

Detects an attempt to exploit CVE-2024-36401, a remote code execution flaw that can run code on the server in GeoServer WPS. The flaw saw mass exploitation against internet-facing GeoServer instances.