GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Summary
Two vulnerabilities in GeoNetwork, an open-source geospatial metadata catalog used by government agencies, can be chained to allow unauthenticated remote code execution. The GeoNetwork project has released fixes for these vulnerabilities in versions 4.4.12 and 4.2.17.
IFF Assessment
The discovery of chained vulnerabilities leading to unauthenticated RCE represents a significant threat to systems handling sensitive geospatial data.
Severity
This is an estimated CVSS score reflecting the potential for unauthenticated, high-impact remote code execution, likely rated as Critical (9.0-10.0) due to the severe impact on confidentiality, integrity, and availability without any user interaction.
Defender Context
This vulnerability highlights the importance of securing specialized software like geospatial metadata catalogs, which can be critical infrastructure for government and agency operations. Defenders should prioritize patching GeoNetwork instances and remain vigilant for any signs of exploitation targeting these systems.