关键漏洞信息 漏洞类型 XML External Entity (XXE) processing vulnerability 影响范围 Package: - (Maven) - (Maven) Affected versions: - - Patched versions: - - 严重性 Severity: High (8.2/10) CVSS v3 base metrics: - Attack vector: Network - Attack complexity: Low - Privileges required: None - User interaction: None - Scope: Unchanged - Confidentiality: High - Integrity: None - Availability: Low CVE ID CVE-2025-30220 弱点 CWE-611 CWE-918 描述 GeoNetwork WFS Index functionality is affected by GeoTools XML External Entity (XXE) vulnerability during schema validation. This vulnerability is particularly severe as the REST API endpoint was not secured, potentially allowing unauthenticated attackers to read sensitive files. 修复措施 GeoNetwork 4.4.8 / 4.2.13. 解决方案 Remove the and jars, disabling the WFS Index functionality. 参考资料 GHSA-826p-4qcq-35vw #8757 #8803 #8812