Impact
GeoNetwork uses the Saxon XSLT processor to render formatters but applies it without secure processing and leaves Java extensions enabled. A malicious formatter written in XSLT can invoke Java’s runtime execution APIs, allowing an attacker to run arbitrary OS commands with the privileges of the GeoNetwork process. The vulnerability thus permits remote code execution as a high‑severity flaw.
Affected Systems
The issue affects the GeoNetwork catalog application before version 4.4.12 and 4.2.17. Any deployment of these older GeoNetwork releases, regardless of operating system, is susceptible to the flaw.
Risk and Exploitability
The CVSS score is 9.1, indicating a critical impact. The EPSS score is 1%, indicating a low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires an authenticated user who can upload a formatter; thus, the flaw can be used by a privileged user through the web interface to deliver a malicious .xsl file and trigger remote code execution.
OpenCVE Enrichment