important · Edge — Geoportals
Two GeoNetwork flaws compose into unauthenticated operating-system command execution.
Affects
GeoNetwork, a self-hosted geospatial metadata catalog commonly deployed as an agency or government geoportal, including its official Docker image.
An unprotected upload stores an attacker formatter, after which Saxon evaluates its Java extension functions without secure-processing restrictions.
Detail and 3 sources
A working chain and packet capture were reported, exploitation is recorded from September 3, and fixes are available.
Sources
ResearchNew exploits and detections for Citrix NetScaler, PaperCut, Sangoma Switchvox, CUPS, Cudy routers, and more. - Initial AccessCode / PoCRemote Code Execution via unsafe Saxon XSLT processor configuration in formatter · Advisory · geonetwork/core-geonetwork · GitHubSecondaryGeoNetwork missing authorization composes with unsafe XSLT into unauthenticated RCE