Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q595-r7rh-mc9h

Опубликовано: 14 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 6.5

Описание

Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests.

Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests.

EPSS

Процентиль: 12%
0.00039
Низкий

8.7 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 6.5
nvd
25 дней назад

Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests.

EPSS

Процентиль: 12%
0.00039
Низкий

8.7 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-611