Unauthenticated RCE in GeoNetwork through an uploaded XSLT formatter
Attack Techniques & MethodsYesterday, 12:53
GeoNetwork is a Java application for publishing and searching geospatial metadata. It uses XSLT-based formatters to render public records. The main finding turns that feature into unauthenticated command execution by chaining a missing authorization check on formatter creation with Saxon's ability to call Java methods. The article also documents an independent SSRF and reflected XSS.
• XSLT-to-RCE chain — Most
FormatterAdminApi methods required @PreAuthorize, but addFormatter did not. An anonymous user could upload a stylesheet and invoke it through the public rendering endpoint using any record UUID returned by GeoNetwork search. Saxon allowed external Java functions, so the stylesheet could call java.lang.Runtime.exec() or java.lang.ProcessBuilder. The author demonstrated a reverse shell on version 4.4.11; commands ran with the privileges of the GeoNetwork process.• SSRF — The SLD import endpoint issued an HTTP GET to a caller-controlled URL without validating the scheme or destination. This allowed requests to internal services. When the response contained valid XML, GeoNetwork returned its contents to the caller; other responses still provided a blind SSRF primitive.
• Reflected XSS —
catalog.search inserted uiconfig directly into an inline JavaScript call. An expression such as (payload,{}) could execute the payload while returning the object expected by the surrounding code. Opening a crafted link therefore ran JavaScript in the GeoNetwork origin, where a script-readable XSRF token could be used for protected requests as the victim.Products
More