Описание
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI controlled vocabulary servlet is vulnerable to an open redirect attack, where an attacker can craft a malicious URL that looks like a legitimate DSpace/repository URL. When that URL is clicked by the target, it redirects them to a site of the attacker's choice. This issue has been patched in versions 5.11 and 6.4. Users are advised to upgrade. There are no known workaround for this vulnerability.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.0 (включая) до 5.10 (включая)Версия от 6.0 (исключая) до 6.4 (исключая)
Одно из
cpe:2.3:a:duraspace:dspace:*:*:*:*:*:*:*:*
cpe:2.3:a:duraspace:dspace:*:*:*:*:*:*:*:*
EPSS
Процентиль: 49%
0.00263
Низкий
7.1 High
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-601
Связанные уязвимости
CVSS3: 7.1
github
больше 3 лет назад
JSPUI's controlled vocabulary feature vulnerable to Open Redirect before v6.4 and v5.11
EPSS
Процентиль: 49%
0.00263
Низкий
7.1 High
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-601