SCA: security update for org.geonetwork-opensource:geonetwork (GHSA-pjp7-q6wp-97qx)

medium Tenable Self-Hosted Container Security Plugin ID 445520

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and
4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and
KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This
issue is fixed in versions 4.2.16 and 4.4.11. (CVE-2026-53573)

Solution

Update the org.geonetwork-opensource:geonetwork library and its related packages to version 4.2.16 or later.

See Also

https://github.com/advisories/GHSA-pjp7-q6wp-97qx

Plugin Details

Severity: Medium

ID: 445520

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/1/2026

Updated: 8/1/2026

Risk Information

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2026-53573

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 4.8

Threat Score: 1.1

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/31/2026

Vulnerability Publication Date: 7/31/2026

Reference Information

CVE: CVE-2026-53573

cwe: CWE-601