Information Disclosure in GeoNetwork Catalog Application by GeoNetwork
CVE-2024-32037

NONE

Key Information:

Vendor

Geonetwork

Vendor
CVE Published:
11 February 2025

What is CVE-2024-32037?

The GeoNetwork catalog application has a vulnerability that allows the exposure of sensitive information about the Elasticsearch software being used on the server. In versions prior to 4.2.10 and 4.4.5, the response headers from the search endpoint inadvertently disclose this information. This exposure could aid potential attackers in identifying the software architecture and increase the risk of a targeted intrusion. Users are advised to upgrade to GeoNetwork version 4.2.10 or newer to mitigate this security risk, as no workarounds are available.

Affected Version(s)

core-geonetwork < 4.2.10 < 4.2.10

core-geonetwork >= 4.4.0, < 4.4.5 < 4.4.0, 4.4.5

References

CVSS V3.1

Score:
Severity:
NONE
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.