VDB
KO
CRITICAL 9.8

GHSA-mqjf-5f49-2fjh

GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers

Quick fix

GHSA-mqjf-5f49-2fjh — org.geotools.jdbc:gt-jdbc-postgis: upgrade to the fixed version with the command below.

# pom.xml: bump <version>35.1</version> for org.geotools.jdbc:gt-jdbc-postgis

Details

### Summary

An SQL Injection Vulnerability has been found when executing OGC Filters with PostGIS DataStore implementation:

* `jsonArrayContains` function Requires PostGIS 12 or greater with a String or JSON field

For PostGIS 12 and greater `jsonArrayContains(<column>, <pointer>, <value>)` function writes `<value>` into generated SQL without escaping.

### Patches

* GeoTools 35.1 * GeoTools 33.5 * GeoTools 34.4

### Mitigation

No mitigation is available:

* To limit scope of SQL Injection the PostGIS connection pool should be configured with limited rights.

### Impact

This vulnerability can lead to execution of arbitrary SQL expressions in the database.

### References

* https://osgeo-org.atlassian.net/browse/GEOT-7958 * https://osgeo-org.atlassian.net/browse/GEOT-7959 * https://github.com/geotools/geotools/pull/5829 * https://osgeo-org.atlassian.net/browse/GEOT-7589

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven / org.geotools.jdbc:gt-jdbc-postgis
Introduced in: 35.0 Fixed in: 35.1
Fix # pom.xml: bump <version>35.1</version> for org.geotools.jdbc:gt-jdbc-postgis
Maven / org.geotools.jdbc:gt-jdbc-postgis
Introduced in: 34.0 Fixed in: 34.5
Fix # pom.xml: bump <version>34.5</version> for org.geotools.jdbc:gt-jdbc-postgis
Maven / org.geotools.jdbc:gt-jdbc-postgis
Introduced in: 30.5 Fixed in: 33.6
Fix # pom.xml: bump <version>33.6</version> for org.geotools.jdbc:gt-jdbc-postgis

References