CVE-2024-32037

GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to be easily identified. GeoNetwork 4.4.5 and 4.2.10 fix this issue. No known workarounds are available.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:osgeo:geonetwork:*:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:geonetwork:*:*:*:*:*:*:*:*

History

17 Apr 2026, 18:08

Type Values Removed Values Added
First Time Osgeo geonetwork
Osgeo
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:osgeo:geonetwork:*:*:*:*:*:*:*:*
References () https://docs.geonetwork-opensource.org/4.4/api/search - () https://docs.geonetwork-opensource.org/4.4/api/search - Product
References () https://github.com/geonetwork/core-geonetwork/releases/tag/4.2.10 - () https://github.com/geonetwork/core-geonetwork/releases/tag/4.2.10 - Release Notes
References () https://github.com/geonetwork/core-geonetwork/releases/tag/4.4.5 - () https://github.com/geonetwork/core-geonetwork/releases/tag/4.4.5 - Release Notes
References () https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-52rf-25hq-5m33 - () https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-52rf-25hq-5m33 - Vendor Advisory

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) GeoNetwork es una aplicación de catálogo para administrar recursos referenciados espacialmente. En versiones anteriores a 4.2.10 y 4.4.5, los encabezados de respuesta del endpoint de búsqueda contienen información sobre el software Elasticsearch en uso. Esta información es valiosa desde el punto de vista de la seguridad porque permite identificar fácilmente el software utilizado por el servidor. GeoNetwork 4.4.5 y 4.2.10 solucionan este problema. No se conocen workarounds.

11 Feb 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 22:15

Updated : 2026-04-17 18:08


NVD link : CVE-2024-32037

Mitre link : CVE-2024-32037

CVE.ORG link : CVE-2024-32037


JSON object : View

Products Affected

osgeo

  • geonetwork
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo