AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-24846

CRITICAL · CVSS 9.1 EPSS 1.22% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-04-14 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.1. It affects Java. Public exploit code or proof-of-concept references have been detected in its references. It may be remotely exploitable.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2022-24846
Severity
CRITICAL
CVSS
9.1
EPSS
1.22%
Java

Original NVD Description

GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code execution. While in GeoWebCache the JNDI strings are provided via local configuration file, in GeoServer a user interface is provided to perform the same, that can be accessed remotely, and requires admin-level login to be used. These lookup are unrestricted in scope and can lead to code execution. The lookups are going to be restricted in GeoWebCache 1.21.0, 1.20.2, 1.19.3.

Related CVEs

Other vulnerabilities affecting the same vendor(s)