PT-2026-2375 · Geonetwork+2 · Geonetwork+1
Amel Bouziane-Leblond
·
Published
2026-01-13
·
Updated
2026-02-27
·
CVE-2022-50899
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Geonetwork versions 3.10 through 4.2.0
Description
Geonetwork contains a flaw in its PDF rendering process related to XML external entities. This allows attackers to retrieve arbitrary files from the server. The issue stems from an insecure XML parser that can be exploited by crafting malicious XML documents with external entity references. Specifically, attackers can read system files through the
baseURL parameter when making PDF creation requests.Recommendations
Versions prior to 4.2.1 should be updated.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geonetwork
Core-Geonetwork