GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Summary

Two vulnerabilities in GeoNetwork, an open-source geospatial metadata catalog used by government agencies, can be chained to allow unauthenticated remote code execution. The GeoNetwork project has released fixes for these vulnerabilities in versions 4.4.12 and 4.2.17.

IFF Assessment

FOE

The discovery of chained vulnerabilities leading to unauthenticated RCE represents a significant threat to systems handling sensitive geospatial data.

Severity

9.8 Critical (AI Estimated)

This is an estimated CVSS score reflecting the potential for unauthenticated, high-impact remote code execution, likely rated as Critical (9.0-10.0) due to the severe impact on confidentiality, integrity, and availability without any user interaction.

Defender Context

This vulnerability highlights the importance of securing specialized software like geospatial metadata catalogs, which can be critical infrastructure for government and agency operations. Defenders should prioritize patching GeoNetwork instances and remain vigilant for any signs of exploitation targeting these systems.

Read Full Story →