Vulnerability Database

309,364

Total vulnerabilities in the database

GeoNetwork affected by XML External Entity (XXE) processing vulnerability in WFS indexing REST API endpoint

Impact

GeoNetwork WFS Index functionality is affected by GeoTools XML External Entity (XXE) vulnerability during schema validation.

This vulnerability is particularly severe as the REST API endpoint was not secured, potentially allowing unauthenticated attackers to read sensitive files

Patches

GeoNetwork 4.4.8 / 4.2.13.

Workarounds

Remove the gn-wfsfeature-harvester and gn-camelPeriodicProducer jars, disabling the WFS Index functionality.

References

  • GHSA-826p-4gcg-35vw
  • https://github.com/geonetwork/core-geonetwork/pull/8757
  • https://github.com/geonetwork/core-geonetwork/pull/8803
  • https://github.com/geonetwork/core-geonetwork/pull/8812

CVSS v3:

  • Severity: Unknown
  • Score:
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L