core-geonetwork vulnerability

GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.

Published 31 Jul 2026Updated 10 Sep 20267 sources
CVSS 4.8

Source timeline

CVE record published by NVDView source ↗