GeoNetwork affected by XML External Entity (XXE) processing vulnerability in WFS indexing REST API endpoint
High severity
GitHub Reviewed
Published
Jun 10, 2025
in
geonetwork/core-geonetwork
•
Updated Jun 10, 2025
Description
Published to the GitHub Advisory Database
Jun 10, 2025
Reviewed
Jun 10, 2025
Last updated
Jun 10, 2025
Impact
GeoNetwork WFS Index functionality is affected by GeoTools XML External Entity (XXE) vulnerability during schema validation.
This vulnerability is particularly severe as the REST API endpoint was not secured, potentially allowing unauthenticated attackers to read sensitive files
Patches
GeoNetwork 4.4.8 / 4.2.13.
Workarounds
Remove the
gn-wfsfeature-harvester
andgn-camelPeriodicProducer
jars, disabling the WFS Index functionality.References
References