QID 982291
QID 982291: Java (maven) Security Update for org.dspace:dspace-xmlui (GHSA-4m9r-5gqp-7j82)
The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack with two or more arbitrary characters and a colon before a pathname, as demonstrated by a themes/Reference/aa:etc/passwd URI.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4m9r-5gqp-7j82 for updates pertaining to this vulnerability.
Vendor References
- GHSA-4m9r-5gqp-7j82 -
github.com/advisories/GHSA-4m9r-5gqp-7j82
CVEs related to QID 982291
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4m9r-5gqp-7j82 | org.dspace:dspace-xmlui |
|