CVE-2024-32037: GeoNetwork vulnerable to search end-point information disclosure in response headers
Impact
The search end-point response headers contain information about Elasticsearch software in use. This information is sensitive from a security point of view because it allows software used by the server to be easily identified.
Patches
GeoNetwork 4.4.5 / 4.2.10
Workarounds
None
References - CVE-2024-32037 - Search service
Credits
- Ministry of Economic Affairs and Climate Policy, The Netherlands.
Other sources
GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to be easily identified. GeoNetwork 4.4.5 and 4.2.10 fix this issue. No known workarounds are available.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32037?
CVE-2024-32037 has been categorized as a moderate severity vulnerability due to the exposure of sensitive software information.
How do I fix CVE-2024-32037?
To remediate CVE-2024-32037, upgrade GeoNetwork to version 4.4.5 or 4.2.10.
What systems are affected by CVE-2024-32037?
CVE-2024-32037 affects GeoNetwork versions prior to 4.2.10 and 4.4.5.
What information is exposed by CVE-2024-32037?
CVE-2024-32037 exposes response headers containing sensitive details about the Elasticsearch software in use.
Can CVE-2024-32037 be exploited remotely?
Yes, CVE-2024-32037 can potentially be exploited remotely due to the nature of the exposed information.