CVE-2024-32037

GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to be easily identified. GeoNetwork 4.4.5 and 4.2.10 fix this issue. No known workarounds are available.
CVSS

No CVSS.

Configurations

No configuration.

History

11 Feb 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 22:15

Updated : 2025-02-11 22:15


NVD link : CVE-2024-32037

Mitre link : CVE-2024-32037

CVE.ORG link : CVE-2024-32037


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor