core-geonetwork vulnerability

GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.

Published 31 Jul 2026Updated 10 Sep 20267 sources
CVSS 4.8

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.