VYPR

Dspace

by Duraspace

Source repositories

CVEs (9)

  • CVE-2016-10726HigJul 10, 2018
    risk 0.49cvss 7.5epss 0.03

    The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack with two or more arbitrary characters and a colon before a pathname, as demonstrated by a themes/Reference/aa:etc/passwd URI.

  • CVE-2022-31194HigAug 1, 2022
    risk 0.46cvss 8.2epss 0.01

    DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI resumable upload implementations in SubmissionController and FileUploadRequest are vulnerable to multiple path…

  • CVE-2022-31195HigAug 1, 2022
    risk 0.40cvss 7.2epss 0.01

    DSpace open source software is a repository application which provides durable access to digital resources. In affected versions the ItemImportServiceImpl is vulnerable to a path traversal vulnerability. This means a malicious SAF (simple archive format) package could cause a…

  • CVE-2021-41189HigOct 29, 2021
    risk 0.40cvss 7.2epss 0.02

    DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up to become system administrator. This vulnerability only exists in 7.0 and does not impact 6.x or below. This issue is patched in…

  • CVE-2022-31193HigAug 1, 2022
    risk 0.39cvss 7.1epss 0.01

    DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI controlled vocabulary servlet is vulnerable to an open redirect attack, where an attacker can craft a malicious URL…

  • CVE-2022-31192HigAug 1, 2022
    risk 0.39cvss 7.1epss 0.01

    DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI "Request a Copy" feature does not properly escape values submitted and stored from the "Request a Copy" form. This…

  • CVE-2022-31191HigAug 1, 2022
    risk 0.39cvss 7.1epss 0.01

    DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI spellcheck "Did you mean" HTML escapes the data-spell attribute in the link, but not the actual displayed text.…

  • CVE-2022-31189MedAug 1, 2022
    risk 0.28cvss 5.3epss 0.01

    DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. When an "Internal System Error" occurs in the JSPUI, then entire exception (including stack trace) is available. Information in…

  • CVE-2022-31190MedAug 1, 2022
    risk 0.28cvss 5.3epss 0.01

    DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace. In affected versions metadata on a withdrawn Item is exposed via the XMLUI "mets.xml" object, as long as you know the handle/URL…