CVE-2024-36401 (GeoServer RCE)
<p>CVE-2024-36401 is a critical Remote Code Execution vulnerability in GeoServer, specifically targeting the Web Feature Service (WFS) endpoint. By sending a specially crafted GET request, an attacker can execute arbitrary Java code via the valueReference parameter of a WFS request. This allows attackers to run system-level commands remotely on the server.</p>