Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests.
Metrics
Affected Vendors & Products
References
History
Wed, 14 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Geonetwork
Geonetwork opensource Geonetwork-opensource Geonetwork-opensource geonetwork |
|
| Vendors & Products |
Geonetwork
Geonetwork opensource Geonetwork-opensource Geonetwork-opensource geonetwork |
Tue, 13 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests. | |
| Title | Geonetwork 4.2.0 - XML External Entity (XXE) | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-01-13T22:51:45.416Z
Updated: 2026-01-14T19:20:51.974Z
Reserved: 2026-01-10T15:05:18.988Z
Link: CVE-2022-50899
Updated: 2026-01-14T15:52:31.779Z
Status : Awaiting Analysis
Published: 2026-01-13T23:15:52.007
Modified: 2026-01-14T16:25:12.057
Link: CVE-2022-50899
No data.