GHSA-mqjf-5f49-2fjhCriticalCVSS 9.8
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
🔗 CVE IDs covered (1)
📋 Description
Summary
An SQL Injection Vulnerability has been found when executing OGC Filters with PostGIS DataStore implementation:
jsonArrayContainsfunction
Requires PostGIS 12 or greater with a String or JSON field
For PostGIS 12 and greater jsonArrayContains(<column>, <pointer>, <value>) function writes <value> into generated SQL without escaping.
Patches
- GeoTools 35.1
- GeoTools 33.5
- GeoTools 34.4
Mitigation
No mitigation is available:
- To limit scope of SQL Injection the PostGIS connection pool should be configured with limited rights.
Impact
This vulnerability can lead to execution of arbitrary SQL expressions in the database.
References
- https://osgeo-org.atlassian.net/browse/GEOT-7958
- https://osgeo-org.atlassian.net/browse/GEOT-7959
- https://github.com/geotools/geotools/pull/5829
- https://osgeo-org.atlassian.net/browse/GEOT-7589
🎯 Affected products3
- maven/org.geotools.jdbc:gt-jdbc-postgis:= 35.0
- maven/org.geotools.jdbc:gt-jdbc-postgis:>= 34.0, < 34.5
- maven/org.geotools.jdbc:gt-jdbc-postgis:>= 30.5, < 33.6
🔗 References (10)
- https://github.com/geotools/geotools/security/advisories/GHSA-mqjf-5f49-2fjh
- https://github.com/geotools/geotools/pull/5829
- https://github.com/geotools/geotools/commit/d821c4d321dd91c22e31fcd5b1ce676645da5176
- https://github.com/geotools/geotools/releases/tag/33.6
- https://github.com/geotools/geotools/releases/tag/34.5
- https://github.com/geotools/geotools/releases/tag/35.1
- https://osgeo-org.atlassian.net/browse/GEOT-7589
- https://osgeo-org.atlassian.net/browse/GEOT-7958
- https://osgeo-org.atlassian.net/browse/GEOT-7959
- https://github.com/advisories/GHSA-mqjf-5f49-2fjh