Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g628-r368-6vh7 | GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection |
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Geoserver
Geoserver geoserver |
|
| Vendors & Products |
Geoserver
Geoserver geoserver |
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue. | |
| Title | GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection | |
| Weaknesses | CWE-502 CWE-74 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-24T03:56:02.624Z
Reserved: 2025-02-26T18:11:52.306Z
Link: CVE-2025-27511
Updated: 2026-06-18T15:57:06.841Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:56:02Z
Github GHSA