CVE-2021-28398
Summary
| CVE | CVE-2021-28398 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-05 17:15:00 UTC |
| Updated | 2022-10-01 02:18:00 UTC |
| Description | A privileged attacker in GeoNetwork before 3.12.0 and 4.x before 4.0.4 can use the directory harvester before-script to execute arbitrary OS commands remotely on the hosting infrastructure. A User Administrator or Administrator account is required to perform this. This occurs in the runBeforeScript method in harvesters/src/main/java/org/fao/geonet/kernel/harvest/harvester/localfilesystem/LocalFilesystemHarvester.java. The earliest affected version is 3.4.0. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Remote Code Execution through Before-Script field in Local Filesystem Harvester · Advisory · geonetwork/core-geonetwork · GitHub |
CONFIRM |
github.com |
|
| GitHub - geonetwork/core-geonetwork: GeoNetwork is a catalog application to manage spatially referenced resources. It provides powerful metadata editing and search functions as well as an interactive web map viewer. It is currently used in numerous Spatial Data Infrastructure initiatives across the world. |
MISC |
github.com |
|
| Home — GeoNetwork opensource |
MISC |
geonetwork-opensource.org |
|
| Version 3.6.0 — GeoNetwork opensource v3.10 GeoNetwork Documentation |
MISC |
geonetwork-opensource.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730700 GeoNetwork OS Command Injection Vulnerbility