CVE-2026-58400

Lưu ý: Dữ liệu này chỉ có tính chất tham khảo, phục vụ nghiên cứu an ninh mạng.CyStack khuyến nghị người dùng không sử dụng các thông tin này nhằm các mục đích bất hợp pháp

Lỗ hổng CVE-2026-58400 là gì?

Lỗ hổng CVE-2026-58400 là lỗ hổng thuộc các loại Improper Control of Generation of Code ('Code Injection') và Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection'), ảnh hưởng tới core-geonetwork (phiên bản bị ảnh hưởng: >= 4.3.0, < 4.4.12 và < 4.2.17). Lỗ hổng này được xếp hạng ở mức Nghiêm trọng, với điểm CVSS 9.1. Các nguồn hiện có chưa ghi nhận lỗ hổng này bị khai thác.

Đang phân tích dữ liệu...

Giới thiệu chung

Dữ liệu gốc

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (FEATURE_SECURE_PROCESSING) and without disabling Java extension functions (ALLOW_EXTERNAL_FUNCTIONS). Any stylesheet loaded by GeoNetwork can therefore invoke java.lang.Runtime.exec() or java.lang.ProcessBuilder directly, achieving arbitrary command execution as the GeoNetwork process user. A user with sufficient privileges to upload a formatter can deliver a .xsl file containing Java extension call that execute arbitrary OS commands with the privileges of the GeoNetwork process. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.

Sản phẩm và phạm vi ảnh hưởng

Đang phân tích dữ liệu...

Chi tiết kỹ thuật

Đang phân tích dữ liệu...

Khả năng khai thác

Đang phân tích dữ liệu...

Tác động kỹ thuật

Đang phân tích dữ liệu...

Tác động đến tổ chức

Đang phân tích dữ liệu...

Cách khắc phục

Đang phân tích dữ liệu...

Cách phát hiện

Đang phân tích dữ liệu...
Nguồn (9)
Tìm hiểu thêm

Kiểm tra chuyên sâu cùng giải pháp quản lý rủi ro Web toàn diện

Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.

Khám phá CyStack VulnScan