Information Disclosure in GeoNetwork Catalog Application by GeoNetwork
CVE-2024-32037
NONE
What is CVE-2024-32037?
The GeoNetwork catalog application has a vulnerability that allows the exposure of sensitive information about the Elasticsearch software being used on the server. In versions prior to 4.2.10 and 4.4.5, the response headers from the search endpoint inadvertently disclose this information. This exposure could aid potential attackers in identifying the software architecture and increase the risk of a targeted intrusion. Users are advised to upgrade to GeoNetwork version 4.2.10 or newer to mitigate this security risk, as no workarounds are available.
Affected Version(s)
core-geonetwork < 4.2.10 < 4.2.10
core-geonetwork >= 4.4.0, < 4.4.5 < 4.4.0, 4.4.5
