PT-2025-26488 · Maven · Org.Geonetwork-Opensource:Gn-Web-App+1
Publicado
2025-06-10
·
Atualizado
2025-06-10
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L |
Impact
GeoNetwork WFS Index functionality is affected by GeoTools XML External Entity (XXE) vulnerability during schema validation.
This vulnerability is particularly severe as the REST API endpoint was not secured, potentially allowing unauthenticated attackers to read sensitive files
Patches
GeoNetwork 4.4.8 / 4.2.13.
Workarounds
Remove the
gn-wfsfeature-harvester and gn-camelPeriodicProducer jars, disabling the WFS Index functionality.References
Correção
XXE
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Org.Geonetwork-Opensource:Gn-Web-App
Org.Geonetwork-Opensource:Gn-Wfsfeature-Harvester