First published: Mon Sep 05 2022(Updated: )
A privileged attacker in GeoNetwork before 3.12.0 and 4.x before 4.0.4 can use the directory harvester before-script to execute arbitrary OS commands remotely on the hosting infrastructure. A User Administrator or Administrator account is required to perform this. This occurs in the runBeforeScript method in harvesters/src/main/java/org/fao/geonet/kernel/harvest/harvester/localfilesystem/LocalFilesystemHarvester.java. The earliest affected version is 3.4.0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Osgeo Geonetwork | >=3.4.0<3.12.0 | |
Osgeo Geonetwork | >=4.0.0<4.0.4 | |
Osgeo Geonetwork | =4.0.0-alpha1 | |
Osgeo Geonetwork | =4.0.0-alpha2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28398 is a vulnerability in GeoNetwork before version 3.12.0 and 4.x before 4.0.4 that allows a privileged attacker to execute arbitrary OS commands remotely on the hosting infrastructure.
The severity of CVE-2021-28398 is high with a CVSS score of 7.2.
CVE-2021-28398 affects GeoNetwork versions before 3.12.0 and 4.x before 4.0.4, allowing a privileged attacker to execute arbitrary OS commands remotely on the hosting infrastructure.
To fix CVE-2021-28398, it is recommended to upgrade to GeoNetwork version 3.12.0 or version 4.0.4 or later.
More information about CVE-2021-28398 can be found on the official GeoNetwork website and in the GeoNetwork change log.