GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.
| Vendor | Product | Versions |
|---|---|---|
| geonetwork | core-geonetwork | >= 3.12.0, <= 3.12.12, >= 4.0.0-alpha.1, <= 4.0.6, >= 4.2.0, < 4.2.16, >= 4.4.0, < 4.4.11 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| maven | org.geonetwork-opensource:geonetwork | GHSA | 85% |
| open source | open source keycloak | cert_advisory | 90% |
Loading…