CVE-2021-41189
Summary
| CVE | CVE-2021-41189 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-29 18:15:00 UTC |
| Updated | 2021-11-03 12:47:00 UTC |
| Description | DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up to become system administrator. This vulnerability only exists in 7.0 and does not impact 6.x or below. This issue is patched in version 7.1. As a workaround, users of 7.0 may temporarily disable the ability for community or collection administrators to manage permissions or workflows settings. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Merge pull request from GHSA-cf2j-vf36-c6w8 · DSpace/DSpace@c3bea16 · GitHub | MISC | github.com | |
| REST service returns wrong object for the "Anonymous" group · Issue #7928 · DSpace/DSpace · GitHub | MISC | github.com | |
| Fix for GHSA-cf2j-vf36-c6w8 · DSpace/DSpace@277b499 · GitHub | MISC | github.com | |
| Communities and collections administrators can escalate their privilege up to system administrator · Advisory · DSpace/DSpace · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980119 Java (maven) Security Update for org.dspace:dspace-api (GHSA-cf2j-vf36-c6w8)