Description
GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.
Severity (CVSS)
| Base score | 4.8 |
|---|---|
| Severity | Medium |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N |
| Provided by | CNA |
Weaknesses
- CWE-601 — CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
Affected products
| Vendor | Product | Versions |
|---|---|---|
| geonetwork | core-geonetwork | >= 3.12.0, <= 3.12.12; >= 4.0.0-alpha.1, <= 4.0.6; >= 4.2.0, < 4.2.16; >= 4.4.0, < 4.4.11 |
References
- https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-pjp7-q6wp-97qx (x_refsource_CONFIRM)
- https://github.com/geonetwork/core-geonetwork/pull/9307 (x_refsource_MISC)
- https://github.com/geonetwork/core-geonetwork/pull/9309 (x_refsource_MISC)
- https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd (x_refsource_MISC)
- https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e (x_refsource_MISC)
- https://github.com/geonetwork/core-geonetwork/releases/tag/4.2.16 (x_refsource_MISC)
- https://github.com/geonetwork/core-geonetwork/releases/tag/4.4.11 (x_refsource_MISC)
Generated from the official CVE List on 01 Aug 2026 07:04 UTC.