Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-25157-and-CVE-2023-25158 — GeoServer & GeoTools SQL Injection (CVE-2023-25157 & CVE-2023-25158) | Kitploit
Tools/GitHubGitHub/murataydemir/cve-2023-25157-and-cve-2023-25158
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationDatabase Security
GitHubmurataydemir/cve-2023-25157-and-cve-2023-25158

CVE-2023-25157-and-CVE-2023-25158

GeoServer & GeoTools SQL Injection (CVE-2023-25157 & CVE-2023-25158)

View Repository
144533 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

GeoServer & GeoTools SQL Injection (CVE-2023-25157 & CVE-2023-25158)


This repository contains a detailed description and replication steps of the SQL Injection vulnerabilities found in the GeoServer platform and GeoTools Library. The vulnerability has been assigned the identifier CVE-2023-25157 for GeoServer and CVE-2023-25158 for GeoTools.

GeoServer is an open-source software server written in Java that provides the ability to view, edit, and share geospatial data. It is designed to be a flexible, efficient solution for distributing geospatial data from a variety of sources such as Geographic Information System (GIS) databases, web-based data, and personal datasets.

GeoServer adheres to the Open Geospatial Consortium (OGC) standards for data sharing, including the Web Feature Service (WFS), Web Map Service (WMS), and the Web Coverage Service (WCS). This adherence to standards means that data from GeoServer can be used in a wide variety of applications, from custom-built GIS software to off-the-shelf solutions.

GeoServer is primarily built on the Spring Framework however, also uses a number of other libraries and frameworks, including:

  • GeoTools: An open-source Java library that provides tools for geospatial data. GeoServer uses GeoTools for many of its core functionalities, such as data reading, writing, and transformation.
  • Hibernate Validator: This is used for bean validations.
  • Java Topology Suite (JTS): An open-source Java software library that provides an object model for planar geometry together with a set of fundamental geometric functions. GeoServer uses it for geometric operations such as calculating bounding boxes.
  • Apache Wicket: This is used for the web admin interface. It's a component-based web application framework similar to JavaServer Faces and Tapestry.
  • Log4J: This is used for logging.

Vulnerabilities


The vulnerabilities in question are deeply embedded within the filter and function expressions defined by the Open Geospatial Consortium (OGC) standards. These expressions form the backbone of geospatial data querying and manipulation, playing a pivotal role in the functionality of systems like GeoServer and GeoTools.

When these vulnerabilities are exploited, they can lead to serious security breaches. Unauthorized disclosure of information is a primary concern, as attackers can potentially access sensitive data stored in the database. Unauthorized modification is another potential outcome, with attackers able to manipulate data to their advantage. Furthermore, these vulnerabilities can also facilitate disruption of service, with a successful exploit possibly leading to service unavailability.

The following provides an in-depth analysis of each identified vulnerability. Each vulnerability is explored in detail, discussing its specific characteristics, the conditions that lead to its manifestation, and the potential effects of its exploitation. Here's a detailed breakdown of the vulnerabilities found for GeoServer:

  • PropertyIsLike filter: this vulnerability is present when the PropertyIsLike filter is used with a String field in conjunction with any relational database-based Store, a PostGIS DataStore with encode functions enabled, or any image mosaic with an index stored in a relational database.
  • strEndsWith function: this vulnerability arises when the strEndsWith function is used with a PostGIS DataStore with encode functions enabled.
  • strStartsWith function: this vulnerability is found when the strStartsWith function is used with a PostGIS DataStore with encode functions enabled.
  • FeatureId filter: this vulnerability is present when the FeatureId filter is used with any database table that has a String primary key column and when prepared statements are disabled.
  • jsonArrayContains function: tThi vulnerability is found when the jsonArrayContains function is used with a String or JSON field and with a PostGIS or Oracle DataStore (only in GeoServer 2.22.0 and later versions).
  • DWithin filter: this vulnerability is discovered when the DWithin filter is used with an Oracle DataStore.

And here's a detailed breakdown of the vulnerabilities found for GeoTools:

  • PropertyIsLike filter:
    • requires PostGIS DataStore with encode functions enabled
    • or any JDBCDataStore (all relational databases) with String field (no mitigation)
  • strEndsWith function:
    • requires PostGIS DataStore with encode functions enabled
  • strStartsWith function:
    • requires PostGIS DataStore with encode functions enabled
  • FeatureId filter:
    • requires JDBCDataStore (all relational databases) with prepared statements disabled and table with String primary key (Oracle not affected, SQL Server and MySQL have no settings to enabled prepared statements, PostGIS does)
  • jsonArrayContains function:
    • requires PostGIS and Oracle DataStore with String or JSON field
  • DWithin filter:
    • happens only in Oracle DataStore, no mitigation

Affected Versions


  • GeoServer: < 2.21.4 >= 2.22.0, < 2.22.2 versions are affected CVE-2023-25157 GeoServer SQL Injection vulnerability.
  • GeoTools: < 28.2, < 27.4, <26.7, <25.7, <24.7 versions are affected CVE-2023-25158 GeoTools SQL Injection vulnerability.

Status


  • The updated GeoServer versions 2.21.4, 2.22.2, 2.20.7, 2.19.7, and 2.18.7, encompassing the corrections, are now publicly available.
  • Versions 28.2, 27.4, 26.7, 25.7, and 24.7 of GeoTools, which include the necessary patches, are now available for use.
Download Tool