Description

GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.

Severity (CVSS)

Base score4.8
SeverityMedium
VersionCVSS 4.0
VectorCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Provided byCNA

Weaknesses

  • CWE-601 — CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Affected products

VendorProductVersions
geonetworkcore-geonetwork>= 3.12.0, <= 3.12.12; >= 4.0.0-alpha.1, <= 4.0.6; >= 4.2.0, < 4.2.16; >= 4.4.0, < 4.4.11

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 01 Aug 2026 07:04 UTC.