Impact
DSpace versions from 8.0-rc1 up to but not including 8.4, 9.0-rc1 up to but not including 9.3, and 10-rc1 up to but not including 10.0 contain a path‑traversal flaw in the COAR Notify/LDN service. When an administrator reads an inbound pattern or template, the LDN class interprets the file as an Apache Velocity template without validating its pathname. This allows a trusted administrator to read any file within the file system that the Java process can access, effectively turning the application into a read‑only file exfiltration tool. The weakness is a classic path‑traversal issue identified by CWE‑22.
Affected Systems
The affected product is DSpace DSpace. All release candidates and initial releases from version 8.0‑rc1 until 8.3.x, from 9.0‑rc1 until 9.2.x, and from 10‑rc1 until before 10.0 are vulnerable. These versions lack the patch applied in version 8.4, 9.3, and 10.0 respectively.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.5, indicating a moderate impact. EPSS data is not available and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires that an attacker already possess DSpace administrator credentials, so it is an admin‑credential‑dependent privilege escalation. Given the lack of external attack vectors and the mitigation through credential control, the likelihood of exploitation remains moderate but non‑negligible.
OpenCVE Enrichment
Github GHSA