Description
DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace. In affected versions metadata on a withdrawn Item is exposed via the XMLUI "mets.xml" object, as long as you know the handle/URL of the withdrawn Item. This vulnerability only impacts the XMLUI. Users are advised to upgrade to version 6.4 or newer.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6510 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace. In affected versions metadata on a withdrawn Item is exposed via the XMLUI "mets.xml" object, as long as you know the handle/URL of the withdrawn Item. This vulnerability only impacts the XMLUI. Users are advised to upgrade to version 6.4 or newer. |
Github GHSA |
GHSA-7w85-pp86-p4pq | XMLUI's metadata of withdrawn Items is exposed to anonymous users |
References
History
Wed, 23 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T17:55:48.589Z
Reserved: 2022-05-18T00:00:00.000Z
Link: CVE-2022-31190
Updated: 2024-08-03T07:11:39.629Z
Status : Modified
Published: 2022-08-01T20:15:08.707
Modified: 2024-11-21T07:04:05.330
Link: CVE-2022-31190
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA