Impact
GeoNetwork is a catalog application to manage spatially referenced resources. Until versions 4.2.17 and 4.4.12 the endpoint POST /api/tools/ogc/sld accepted a caller‑supplied WMS server URL and performed an unvalidated server‑side HTTP GET. An anonymous attacker can force GeoNetwork to issue requests to internal hosts that are not publicly reachable. When the fetched response is XML, the endpoint can store and return that body, turning the SSRF into a non‑blind flaw that enables internal data disclosure, authorization bypass, and network reconnaissance. The weakness is a classic Server‑Side Request Forgery and is identified as CWE‑918.
Affected Systems
The vulnerable component is the GeoNetwork core, versions earlier than 4.2.17 and 4.4.12. These releases run the SLD tool endpoint at /api/tools/ogc/sld, which accepts arbitrary URLs. Only the specified earlier versions are affected; the security fix is included in releases 4.2.17 and 4.4.12.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of < 1% suggests a low but non‑zero probability of exploitation. The vulnerability is not listed in CISA KEV. Because the attack vector is an unauthenticated POST to the SLD endpoint with an arbitrary URL, it is straightforward for any attacker who can reach the GeoNetwork service. The ability to reach internal hosts and leak data presents a serious risk to confidentiality and network security.
OpenCVE Enrichment
Github GHSA