PT-2026-66870 · Unknown · Geonetwork
CVE-2026-53573
·
Published
2026-07-31
·
Updated
2026-07-31
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
GeoNetwork versions 3.12.0 through 4.2.15
GeoNetwork versions 4.4.0 through 4.4.10
Description
Unsafe redirect validation in
GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter allows an attacker to redirect users to an external site after login. Although the application attempts to restrict redirect targets to relative, in-application URLs, the validation fails to reject all URL types that cause the browser to leave the origin. An attacker can craft a link to a legitimate OAuth2/OIDC or Keycloak login endpoint that forwards the victim to an arbitrary external host upon completion of the login flow, which can be used for phishing attacks.Recommendations
Update to version 4.2.16 or later.
Update to version 4.4.11 or later.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geonetwork