CVE-2024-32037 – GeoNetwork Elasticsearch Information Disclosure

The following table lists the changes that have been made to the
CVE-2024-32037 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Feb. 11, 2025

    Action Type Old Value New Value
    Added Description GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to be easily identified. GeoNetwork 4.4.5 and 4.2.10 fix this issue. No known workarounds are available.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
    Added CWE CWE-200
    Added Reference https://docs.geonetwork-opensource.org/4.4/api/search
    Added Reference https://github.com/geonetwork/core-geonetwork/releases/tag/4.2.10
    Added Reference https://github.com/geonetwork/core-geonetwork/releases/tag/4.4.5
    Added Reference https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-52rf-25hq-5m33
Share the Post:

Related Posts