PT-2022-9890 · Unknown · Geonetwork

Tyler Sullivan

·

Published

2022-09-05

·

Updated

2022-10-01

·

CVE-2021-28398

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GeoNetwork versions 3.4.0 through 3.12.0 GeoNetwork versions 4.0.0 through 4.0.3
Description A privileged attacker can use the directory harvester before-script to execute arbitrary OS commands remotely on the hosting infrastructure. This requires a User Administrator or Administrator account. The issue occurs in the runBeforeScript method in harvesters/src/main/java/org/fao/geonet/kernel/harvest/harvester/localfilesystem/LocalFilesystemHarvester.java.
Recommendations For GeoNetwork versions 3.4.0 through 3.12.0, update to version 3.12.0 or later. For GeoNetwork versions 4.0.0 through 4.0.3, update to version 4.0.4 or later. As a temporary workaround, consider disabling the runBeforeScript method in the LocalFilesystemHarvester class until a patch is available.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-28398
GHSA-CF8P-C88C-H9JF

Affected Products

Geonetwork