vendor:
Geonetwork
by:
Amel BOUZIANE-LEBLOND
8.8
CVSS
HIGH
XML External Entity (XXE)
611
CWE
Product Name: Geonetwork
Affected Version From: Geonetwork 3.10.X
Affected Version To: Geonetwork 4.2.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Microsoft Windows Server & Linux
2022
Geonetwork 4.2.0 – XML External Entity (XXE)
GeoNetwork 3.1.x through 4.2.0 is vulnerable to XML External Entity (XXE) attack during rendering pdf of map. The XML parser is not configured securely to validate submitted XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server.
Mitigation:
Ensure that XML parsers are configured securely to validate submitted XML documents accepted from an untrusted source.