GeoNetwork 4.4.12 and 4.2.17 released

Jody here acting as vulnerability coordinator.

The release notes have been updated with now published CVE information:

I trust everyone had plenty of time to upgrade!

We appreciate all the work that has gone into reporting and addressing these vulnerabilities. The GeoNetwork coordinated vulnerability disclosure policy is carefully setup to give everyone an opportunity to update prior to public disclosure.

Organizations reporting issues are reminded that GeoNetwork is a community project: and thus in effect self-serve. The magic of having access to the source code is an invitation to participate and make the software better (including addressing security issues found). Those seeking or expecting a vendor relationship can review the professional support providers linked to from our website.