VYPR

Geonetwork

by Osgeo

Source repositories

CVEs (4)

  • CVE-2025-30220CriJun 10, 2025
    risk 0.61cvss 9.9epss 0.57

    GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with…

  • CVE-2021-28398HigSep 5, 2022
    risk 0.47cvss 7.2epss 0.01

    A privileged attacker in GeoNetwork before 3.12.0 and 4.x before 4.0.4 can use the directory harvester before-script to execute arbitrary OS commands remotely on the hosting infrastructure. A User Administrator or Administrator account is required to perform this. This occurs in…

  • CVE-2022-50899MedJan 13, 2026
    risk 0.42cvss 6.5epss 0.00

    Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to…

  • CVE-2024-32037NonFeb 11, 2025
    risk 0.00cvss 0.0epss 0.00

    GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because…