An unauthenticated SQL injection in GeoServer’s jsonArrayContains filter function lets attackers inject arbitrary SQL through public WMS and WFS endpoints, reaching remote code execution on privileged database hosts.
Read more about Emerging Threat: GeoServer Zero-Day SQL Injection via jsonArrayContains