{"id":"CVE-2021-28398","details":"A privileged attacker in GeoNetwork before 3.12.0 and 4.x before 4.0.4 can use the directory harvester before-script to execute arbitrary OS commands remotely on the hosting infrastructure. A User Administrator or Administrator account is required to perform this. This occurs in the runBeforeScript method in harvesters/src/main/java/org/fao/geonet/kernel/harvest/harvester/localfilesystem/LocalFilesystemHarvester.java. The earliest affected version is 3.4.0.","aliases":["GHSA-cf8p-c88c-h9jf"],"modified":"2026-08-07T11:31:24.952300782Z","published":"2022-09-05T17:15:19.083Z","database_specific":{"unresolved_ranges":[{"source":"CPE_STRING","vendor_product":"osgeo:geonetwork","cpes":["cpe:2.3:a:osgeo:geonetwork:4.0.0:alpha1:*:*:*:*:*:*","cpe:2.3:a:osgeo:geonetwork:4.0.0:alpha2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.0.0-alpha1"},{"last_affected":"4.0.0-alpha1"},{"introduced":"4.0.0-alpha2"},{"last_affected":"4.0.0-alpha2"}]}]},"references":[{"type":"WEB","url":"https://geonetwork-opensource.org/"},{"type":"ADVISORY","url":"https://github.com/geonetwork/core-geonetwork"},{"type":"FIX","url":"https://geonetwork-opensource.org/manuals/trunk/en/overview/change-log/version-3.6.0.html"},{"type":"FIX","url":"https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-cf8p-c88c-h9jf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/geonetwork/core-geonetwork","events":[{"introduced":"5b4f72acb979605e3aa49d923fd8e21c8ccf4591"},{"fixed":"72bf9606a19b80dff9cd56fbe3f718a932f21aa3"},{"introduced":"e1c155ae64342f43775bd8c637d88e8594a3efcc"},{"fixed":"1099706d309646607aa32abb11c3624f58043bd7"}],"database_specific":{"extracted_events":[{"introduced":"3.4.0"},{"fixed":"3.12.0"},{"introduced":"4.0.0"},{"fixed":"4.0.4"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:osgeo:geonetwork:*:*:*:*:*:*:*:*"}}],"versions":["4.0.3","4.0.2","4.0.1","4.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-28398.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}