{"id":"CVE-2025-27511","aliases":["GHSA-g628-r368-6vh7"],"title":"GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection","summary":"GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection","severity":"high","cvss":7.2,"cwe":["CWE-74","CWE-502"],"vendor":"geoserver","product":"org.geoserver.extension:gs-db2","ecosystem":"maven","affected":["org.geoserver.extension:gs-db2 < 2.27.0"],"patched":["org.geoserver.extension:gs-db2 2.27.0"],"published":"2026-06-11","updated":"2026-06-11","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-g628-r368-6vh7","references":[{"url":"https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"},{"url":"https://github.com/geoserver/geoserver/releases/tag/2.27.0"},{"url":"https://github.com/advisories/GHSA-g628-r368-6vh7"}],"tags":["ghsa","maven"],"epss":0.01074,"epssPercentile":0.63025,"ingestedAt":"2026-07-07T15:41:59.279Z","slug":"CVE-2025-27511","body":"## Overview\n\n## Summary\n\nAdministrator can perform JNDI attack through specially crafted DB2 jdbc url leading to Remote Code Execution (RCE).\n\n## Impact\n\nIf GeoServer has DB2 extension installed, this vulnerability can lead to executing arbitrary code.\n\n## Details\n\nAuthenticated users can access Vector Data Sources page to creating a new data store through db2 jdbc connection, performing JNDI attack due to unrestricted connection parameters, and then achieve RCE with deserialization of untrusted data.\n\n### Remediation\n\nThis issue has been fixed in this release: https://github.com/geoserver/geoserver/releases/tag/2.27.0.\n\n## References\n\n* https://osgeo-org.atlassian.net/browse/GEOT-7725\n* https://nvd.nist.gov/vuln/detail/cve-2023-27867\n\n## Affected packages\n\n- `org.geoserver.extension:gs-db2 < 2.27.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `org.geoserver.extension:gs-db2 2.27.0`","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}