
CVE-2024-36401-GeoServer Property 表达式注入 Rce woodpecker-framework 插件
Batch detection and exploitation of CVE-2024-36401, supporting custom memory shell injection

Download the source code and execute
mvn package
Place the jar file from target into the plugin folder under woodpecker-framework
If you don't want to compile it yourself, you can directly download CVE-2024-36401-WoodpeckerPlugin-x.x-SNAPSHOT-all.jar from the attachments and place it in the plugin folder under woodpecker-framework

After PoC detection, right-click to send to Exploit

In command=xx,xx is any command to execute
When ismemshelldopen=false, commands are executed; when true, no command is executed

Listener memory shellCustom memory shell injection: Use java-memshell-generator to generate the memory shell, note that the middleware should be Jetty

Or use the JMG Shell Helper plugin

Then replace the xx parameter in memshelldata=xx

For learning and research purposes only. The author is not responsible for any consequences arising from the use of this project.
https://yzddmr6.com/posts/geoserver-memoryshell/
https://blog.csdn.net/qq_45305211/article/details/139717906
https://github.com/kN6jq/WoodpeckerPluginManager