Impact
DSpace repository software, before versions 7.6.7, 8.4, 9.3, and 10.0, accepts aggregated ORE resource URIs without validating their scheme. An attacker with collection administrator rights can supply a malicious URI such as file:///etc/passwd, causing the ORE Ingestion Crosswalk to include local files. The flaw is an input validation issue (CWE-20) that could expose sensitive local filesystem data to privileged users.
Affected Systems
The vulnerability affects DSpace installations running any of the following full releases: 7.6.7 and earlier, 8.4 and earlier, 9.3 and earlier, and 10.0 and earlier. Only systems that use the OAI‑ORE Harvester to ingest aggregated resources are impacted; other components are unaffected.
Risk and Exploitability
The CVSS base score of 4.4 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in CISA KEV, suggesting limited known exploitation. Successful exploitation requires the attacker to already possess collection administrator privileges, so the threat is constrained to users with elevated roles. Nonetheless, the potential to read arbitrary local files warrants prompt mitigation.
OpenCVE Enrichment
Github GHSA