Horizon Alert
Summary of the vulnerability and why it matters
This advisory addresses a critical vulnerability in the GeoTools open-source Java library, which is used for processing geospatial data. The issue, an SQL Injection vulnerability, arises when specific functions are used with PostGIS data. If exploited, this could allow unauthorized parties to manipulate or access data. The primary concern is to confirm if this library is in use and if the affected functions are being utilized, particularly in internet-facing applications.
- Text vulnerability allows data manipulation.
- Understand if GeoTools is in use.
- Confirm relevance and exposure to critical risk.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by sending specially crafted OGC filters to an application that uses the affected GeoTools library with the PostGIS DataStore. This could lead to attackers executing arbitrary SQL commands.
- No authentication or privileges required.
- Malicious OGC filter via `jsonArrayContains`.
- Complete database compromise possible.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an attacker to inject malicious SQL commands when processing geospatial data through the PostGIS DataStore implementation, specifically when using the `jsonArrayContains` function with a string or JSON field and PostGIS 12 or greater. This could lead to unauthorized data access or modification within the geospatial database.
- Geospatial data in PostGIS databases.
- Via unescaped user input in `jsonArrayContains` calls.
- Unauthorized access or modification of data.
Operational Fix
Recommended remediation, mitigation, and detection steps
The GeoTools library, used for geospatial data processing, is susceptible to an SQL Injection vulnerability when interacting with PostGIS. Application owners and platform teams are likely responsible for managing instances of GeoTools. The immediate priority is to identify all deployments, confirm their exposure and criticality, and then plan remediation, prioritizing those systems with the greatest risk.
- Application owners should own the issue.
- Verify PostGIS interaction and data sensitivity.
- Plan remediation based on exposure and criticality.