CVE-2024-32037

NONE
Published Feb 11, 2025 Modified Apr 17, 2026 CWE-200

Description

GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to be easily identified. GeoNetwork 4.4.5 and 4.2.10 fix this issue. No known workarounds are available.

Is your site exposed to CVE-2024-32037?

Run a free security scan — no signup, results in seconds.

Weakness Type (CWE)

CWE-200 CWE-200

Affected Products

Vendor Product
osgeo geonetwork
osgeo geonetwork

References

Frequently Asked Questions

What is CVE-2024-32037? +
GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to be easily identified. GeoNetwork 4.4.5 and 4.2.10 fix this issue. No known workarounds are available.
What products are affected by CVE-2024-32037? +
CVE-2024-32037 affects products from osgeo, specifically: geonetwork. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-32037? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-32037 — free, no signup required.