GeoNetwork
cpe:2.3:a:osgeo:geonetwork:*:*:*:*:*:*:*
- >= 4.4.0, < 4.4.5
- < 4.2.10
A vulnerability exists in GeoNetwork versions prior to 4.2.10 and 4.4.5, where the search endpoint response headers inadvertently reveal details about the Elasticsearch software in use. This information could be exploited to identify the server's software components, potentially leading to security risks.
Exploitation of this vulnerability could allow an attacker to gain insights into the server's software stack, which could be used to identify potential vulnerabilities or attack vectors.
Users can upgrade to GeoNetwork versions 4.4.5 or 4.2.10 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.