← Global Threat Landscape

CVE-2022-24816

CWE-94

Critical

105.0

RPS

Description

JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compile Jiffle scripts from the final application, by removing janino-x.y.z.jar from the classpath.

Source: NVD

Signals

CVSS
10.0
Critical · v3.1
EPSS
99.91%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Jun 2024
Fix commit
Fix commit known
Sources: MoreFixes, FreshFixes
Weakness
CWE-94
Published
13 Apr 2022
Last modified 24 Oct 2025

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2022-24816

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2022-24816 · RPS 105.0 · DevSecure Intelligence