GeoNetwork XXE Vulnerability (CVE-2025-30220) Advisory and Fix
Security AdvisoryCVE-2025-30220HighGeoNetwork
Affected:
- org.geonetwork.opensource:gn-web-app >=4.4.0,<=4.4.7
- org.geonetwork.opensource:gn-wfsfeature-harvester >=4.4.0,<=4.4.7
- org.geonetwork.opensource:gn-web-app >=4.2.0,<=4.2.12
- org.geonetwork.opensource:gn-wfsfeature-harvester >=4.2.0,<=4.2.12
Fixed in:
- 4.4.8
- 4.2.13
Referenced CVEs: CVE-2025-30220 · 9.9 Top EPSS
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.