High severity7.1NVD Advisory· Published Aug 1, 2022· Updated Jun 17, 2026
CVE-2022-31191
CVE-2022-31191
Description
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI spellcheck "Did you mean" HTML escapes the data-spell attribute in the link, but not the actual displayed text. Similarly, the JSPUI autocomplete HTML does not properly escape text passed to it. Both are vulnerable to XSS. This vulnerability only impacts the JSPUI. Users are advised to upgrade. There are no known workarounds for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.dspace:dspace-jspuiMaven | >= 4.0, < 5.11 | 5.11 |
org.dspace:dspace-jspuiMaven | >= 6.0, < 6.4 | 6.4 |
Affected products
3Patches
Vulnerability mechanics
References
7- github.com/DSpace/DSpace/commit/35030a23e48b5946f5853332c797e1c4adea7bb7nvdPatchThird Party AdvisoryWEB
- github.com/DSpace/DSpace/commit/6f75bb084ab1937d094208c55cd84340040bcbb5nvdPatchThird Party AdvisoryWEB
- github.com/DSpace/DSpace/commit/c89e493e517b424dea6175caba54e91d3847fc3anvdPatchThird Party AdvisoryWEB
- github.com/DSpace/DSpace/commit/ebb83a75234d3de9be129464013e998dc929b68dnvdPatchThird Party AdvisoryWEB
- github.com/DSpace/DSpace/security/advisories/GHSA-c558-5gfm-p2r8nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-c558-5gfm-p2r8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-31191ghsaADVISORY
News mentions
0No linked articles in our index yet.