GeoServer RCE Attack

A remote code execution vulnerability within GeoServer is currently under active exploitation, with recent incidents targeting 40,000 sensors. This vulnerability is being exploited by the Earth Baxia APT group, as reported by FortiGuard Recon. The root cause of this vulnerability lies in the absence of proper input validation during request handling, posing a significant risk of system compromise upon successful exploitation.