GHSA-pjp7-q6wp-97qx

Suggest an improvement
Source
https://github.com/advisories/GHSA-pjp7-q6wp-97qx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-pjp7-q6wp-97qx/GHSA-pjp7-q6wp-97qx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pjp7-q6wp-97qx
Aliases
Published
2026-07-31T22:16:34Z
Modified
2026-07-31T22:30:23.102569731Z
Severity
  • 0.0 (None) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N CVSS Calculator
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N CVSS Calculator
Summary
core-geonetwork has an Open Redirect Bypass
Details

Summary

GeoNetwork's post-login redirect handling can be bypassed to redirect users to an attacker-controlled external site, even though the code attempts to restrict redirect targets to relative, in-application URLs. This affects both supported SSO login methods: OAuth2/OIDC and Keycloak.

Details

Both the OAuth2/OIDC and Keycloak login filters validate the client-supplied post-login redirect target before forwarding the browser to it, but the validation does not correctly reject every kind of URL that causes the browser to leave the GeoNetwork origin. As a result, a value that is treated as a safe, in-application relative path by the filter can still cause the browser to be redirected to an external, attacker-controlled host.

Impact

An attacker can craft a link to a legitimate GeoNetwork OAuth2/OIDC or Keycloak login endpoint that, after the login flow completes, redirects the victim to an arbitrary external site. This can be used for phishing (e.g., presenting a fake login form) or to chain into other attacks hosted externally. This does not bypass authentication or expose GeoNetwork data directly; the impact is Open Redirect (CWE-601).

GeoNetwork 3.x and 4.0.x are archived/unmaintained and will not receive a fix for this issue. Instances running those lines should upgrade to a supported release (4.2.16 or later, or 4.4.11 or later).

Database specific
{
    "cwe_ids": [
        "CWE-601"
    ],
    "github_reviewed_at": "2026-07-31T22:16:34Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "nvd_published_at": null
}
References

Affected packages

Maven
org.geonetwork-opensource:geonetwork

Package

Name
org.geonetwork-opensource:geonetwork
View open source insights on deps.dev
Purl
pkg:maven/org.geonetwork-opensource/geonetwork

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.12.0
Last affected
3.12.12

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-pjp7-q6wp-97qx/GHSA-pjp7-q6wp-97qx.json"
org.geonetwork-opensource:geonetwork

Package

Name
org.geonetwork-opensource:geonetwork
View open source insights on deps.dev
Purl
pkg:maven/org.geonetwork-opensource/geonetwork

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0-alpha.1
Last affected
4.0.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-pjp7-q6wp-97qx/GHSA-pjp7-q6wp-97qx.json"
org.geonetwork-opensource:geonetwork

Package

Name
org.geonetwork-opensource:geonetwork
View open source insights on deps.dev
Purl
pkg:maven/org.geonetwork-opensource/geonetwork

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
4.2.16

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-pjp7-q6wp-97qx/GHSA-pjp7-q6wp-97qx.json"
last_known_affected_version_range
"<= 4.2.15"
org.geonetwork-opensource:geonetwork

Package

Name
org.geonetwork-opensource:geonetwork
View open source insights on deps.dev
Purl
pkg:maven/org.geonetwork-opensource/geonetwork

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.4.0
Fixed
4.4.11

Database specific

last_known_affected_version_range
"<= 4.4.10"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-pjp7-q6wp-97qx/GHSA-pjp7-q6wp-97qx.json"