Vulnerabilities (CVE)

Filtered by vendor Geosolutionsgroup
Filtered by product Jai-ext
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-24816 1 Geosolutionsgroup 1 Jai-ext 2025-10-24 7.5 HIGH 10.0 CRITICAL
JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compi ...

Show More