CVE-2024-32037 NONE

CVE-2024-32037: GeoNetwork vulnerable to search end-point information disclosure in response headers

Vendor Geonetwork
Product core-geonetwork
Weakness CWE-200 · Info exposure
Published February 11, 2025
Last update February 12, 2025

CVSS base score

0.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N

What the vulnerability does

01Description

GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to be easily identified. GeoNetwork 4.4.5 and 4.2.10 fix this issue. No known workarounds are available.

Key dates

02Disclosure timeline

February 11, 2025 CVE published
February 12, 2025 Record updated