newsמקור: The Hacker News2.9.2026
פרצות ב-GeoNetwork מאפשרות RCE ללא אימות בשרתי גאו-פורטלים ממשלתיים
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

◆ סיכום AI
נמצאו שתי פרצות אבטחה ב-GeoNetwork, קטלוג מטא-נתונים גיאומרחבי בקוד פתוח. ניתן לשרשר את הפרצות כדי להשיג Remote Code Execution (RCE) ללא צורך באימות. פרצות אלו משפיעות על שרתי עורף רבים של גאו-פורטלים ממשלתיים.
# מהמקור
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and
#vulnerability#rce#open-source-security#geoportal
קרא במקור