PT-2026-2375 · Geonetwork+2 · Geonetwork+1
Amel Bouziane-Leblond
·
Publicado
2026-01-13
·
Atualizado
2026-02-27
·
CVE-2022-50899
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Geonetwork versions 3.10 through 4.2.0
Description
Geonetwork contains a flaw in its PDF rendering process related to XML external entities. This allows attackers to retrieve arbitrary files from the server. The issue stems from an insecure XML parser that can be exploited by crafting malicious XML documents with external entity references. Specifically, attackers can read system files through the
baseURL parameter when making PDF creation requests.Recommendations
Versions prior to 4.2.1 should be updated.
Exploit
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Geonetwork
Core-Geonetwork