VDB
KO
0.0

GHSA-pjp7-q6wp-97qx

core-geonetwork has an Open Redirect Bypass

Quick fix

GHSA-pjp7-q6wp-97qx — org.geonetwork-opensource:geonetwork: upgrade to the fixed version with the command below.

# pom.xml: bump <version>4.2.16</version> for org.geonetwork-opensource:geonetwork

Details

### Summary GeoNetwork's post-login redirect handling can be bypassed to redirect users to an attacker-controlled external site, even though the code attempts to restrict redirect targets to relative, in-application URLs. This affects both supported SSO login methods: OAuth2/OIDC and Keycloak.

### Details Both the OAuth2/OIDC and Keycloak login filters validate the client-supplied post-login redirect target before forwarding the browser to it, but the validation does not correctly reject every kind of URL that causes the browser to leave the GeoNetwork origin. As a result, a value that is treated as a safe, in-application relative path by the filter can still cause the browser to be redirected to an external, attacker-controlled host.

### Impact An attacker can craft a link to a legitimate GeoNetwork OAuth2/OIDC or Keycloak login endpoint that, after the login flow completes, redirects the victim to an arbitrary external site. This can be used for phishing (e.g., presenting a fake login form) or to chain into other attacks hosted externally. This does not bypass authentication or expose GeoNetwork data directly; the impact is Open Redirect (CWE-601).

GeoNetwork 3.x and 4.0.x are archived/unmaintained and will not receive a fix for this issue. Instances running those lines should upgrade to a supported release (4.2.16 or later, or 4.4.11 or later).

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven / org.geonetwork-opensource:geonetwork
Introduced in: 3.12.0

No fixed version published yet for org.geonetwork-opensource:geonetwork (maven). Pin to a known-safe version or switch to an alternative.

Maven / org.geonetwork-opensource:geonetwork
Introduced in: 4.0.0-alpha.1

No fixed version published yet for org.geonetwork-opensource:geonetwork (maven). Pin to a known-safe version or switch to an alternative.

Maven / org.geonetwork-opensource:geonetwork
Introduced in: 4.2.0 Fixed in: 4.2.16
Fix # pom.xml: bump <version>4.2.16</version> for org.geonetwork-opensource:geonetwork
Maven / org.geonetwork-opensource:geonetwork
Introduced in: 4.4.0 Fixed in: 4.4.11
Fix # pom.xml: bump <version>4.4.11</version> for org.geonetwork-opensource:geonetwork

References