GeoNetwork search end-point information disclosure in response headers
Moderate severity
GitHub Reviewed
Published
Feb 11, 2025
in
geonetwork/core-geonetwork
•
Updated Feb 12, 2025
Package
Affected versions
>= 4.4.0, < 4.4.5
< 4.2.10
Patched versions
4.4.5
4.2.10
Description
Published by the National Vulnerability Database
Feb 11, 2025
Published to the GitHub Advisory Database
Feb 11, 2025
Reviewed
Feb 11, 2025
Last updated
Feb 12, 2025
Impact
The search end-point response headers contain information about Elasticsearch software in use. This information is sensitive from a security point of view because it allows software used by the server to be easily identified.
Patches
GeoNetwork 4.4.5 / 4.2.10
Workarounds
None
References
Credits
References