Geonetwork 4.2.0 - XML External Entity (XXE)
Vulnerability Description
Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-50899
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Amel BOUZIANE-LEBLOND
Affected Vendor
GeoNetwork
View all reports →