GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to be easily identified. GeoNetwork 4.4.5 and 4.2.10 fix this issue. No known workarounds are available.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-52rf-25hq-5m33 | GeoNetwork search end-point information disclosure in response headers |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 11 Feb 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to be easily identified. GeoNetwork 4.4.5 and 4.2.10 fix this issue. No known workarounds are available. | |
| Title | GeoNetwork vulnerable to search end-point information disclosure in response headers | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-12T15:37:46.364Z
Reserved: 2024-04-09T15:29:35.939Z
Link: CVE-2024-32037
No data.
Status : Received
Published: 2025-02-11T22:15:27.930
Modified: 2025-02-11T22:15:27.930
Link: CVE-2024-32037
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA