PT-2025-26488 · Maven · Org.Geonetwork-Opensource:Gn-Web-App+1

Publicado

2025-06-10

·

Atualizado

2025-06-10

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

Impact

GeoNetwork WFS Index functionality is affected by GeoTools XML External Entity (XXE) vulnerability during schema validation.
This vulnerability is particularly severe as the REST API endpoint was not secured, potentially allowing unauthenticated attackers to read sensitive files

Patches

GeoNetwork 4.4.8 / 4.2.13.

Workarounds

Remove the gn-wfsfeature-harvester and gn-camelPeriodicProducer jars, disabling the WFS Index functionality.

References

Correção

XXE

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-2P76-GC46-5FVC

Produtos afetados

Org.Geonetwork-Opensource:Gn-Web-App
Org.Geonetwork-Opensource:Gn-Wfsfeature-Harvester