{"id":"CVE-2024-32037","summary":"GeoNetwork vulnerable to search end-point information disclosure in response headers","details":"GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to be easily identified. GeoNetwork 4.4.5 and 4.2.10 fix this issue. No known workarounds are available.","aliases":["GHSA-52rf-25hq-5m33"],"modified":"2026-08-12T03:51:34.695088056Z","published":"2025-02-11T21:50:29.138Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-200"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32037.json"},"references":[{"type":"WEB","url":"https://docs.geonetwork-opensource.org/4.4/api/search"},{"type":"WEB","url":"https://github.com/geonetwork/core-geonetwork/releases/tag/4.2.10"},{"type":"WEB","url":"https://github.com/geonetwork/core-geonetwork/releases/tag/4.4.5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32037.json"},{"type":"ADVISORY","url":"https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-52rf-25hq-5m33"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32037"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/geonetwork/core-geonetwork","events":[{"introduced":"0"},{"fixed":"680b48cd156778c1beaf78917153e470f9d80736"},{"introduced":"19b9edba4f9a5718047d3b17eb874c3ca769c26e"},{"fixed":"d9f211c94a08cd2829ba54be9c9a8d9f19411de3"}],"database_specific":{"cpe":"cpe:2.3:a:osgeo:geonetwork:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.2.10"},{"introduced":"4.4.0"},{"fixed":"4.4.5"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["4.4.4","4.2.9","4.4.3","4.2.8","4.4.2","4.4.1","4.2.7","4.4.0","4.2.6","4.2.5","4.2.4","4.2.3","4.2.2","4.2.1","4.2.0","4.0.6","4.0.5","4.0.4","4.0.3","4.0.2","4.0.1","4.0.0","4.0.0-alpha.2","4.0.0-alpha.1","3.4.2","3.4.1","3.4.0","3.2.0","3.0.0RC0","start-migration","2.6.4","2.6.3","2.6.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-32037.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"}]}