CVE-2026-53573
4.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Summary
GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| geonetwork | core-geonetwork | >= 3.12.0, <= 3.12.12 | affected |
| geonetwork | core-geonetwork | >= 4.0.0-alpha.1, <= 4.0.6 | affected |
| geonetwork | core-geonetwork | >= 4.2.0, < 4.2.16 | affected |
| geonetwork | core-geonetwork | >= 4.4.0, < 4.4.11 | affected |
Weaknesses
- CWE-601: CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
References
- https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-pjp7-q6wp-97qx
- https://github.com/geonetwork/core-geonetwork/pull/9307
- https://github.com/geonetwork/core-geonetwork/pull/9309
- https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd
- https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e
- https://github.com/geonetwork/core-geonetwork/releases/tag/4.2.16
- https://github.com/geonetwork/core-geonetwork/releases/tag/4.4.11
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.