CVE-2022-31190

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/08/2022
Last modified:
24/07/2023

Description

DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace. In affected versions metadata on a withdrawn Item is exposed via the XMLUI "mets.xml" object, as long as you know the handle/URL of the withdrawn Item. This vulnerability only impacts the XMLUI. Users are advised to upgrade to version 6.4 or newer.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:duraspace:dspace:*:*:*:*:*:*:*:* 4.0 (including) 6.4 (excluding)