CVE-2022-50899: Geonetwork 4.2.0 - XML External Entity (XXE)
Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50899?
CVE-2022-50899 is rated as a critical vulnerability due to its potential to allow unauthorized access to sensitive files on the server.
How do I fix CVE-2022-50899?
To fix CVE-2022-50899, upgrade Geonetwork to version 4.2.1 or later, which addresses the XML external entity vulnerability.
What are the potential impacts of CVE-2022-50899?
The potential impacts of CVE-2022-50899 include unauthorized file access and data leakage from the affected server.
Who is affected by CVE-2022-50899?
CVE-2022-50899 affects users of Geonetwork versions 3.10 through 4.2.0.
How can attackers exploit CVE-2022-50899?
Attackers can exploit CVE-2022-50899 by crafting a malicious XML document that is processed by the vulnerable XML parser, leading to file retrieval.