Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-53622

Опубликовано: 15 июл. 2025
Источник: nvd
CVSS3: 5.2
EPSS Низкий

Описание

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.4, 8.2, and 9.1, a path traversal vulnerability is possible during the import of an archive (in Simple Archive Format), either from command-line (./dspace import command) or from the "Batch Import (Zip)" user interface feature. An attacker may craft a malicious Simple Archive Format (SAF) package where the contents file references any system files (using relative traversal sequences) which are readable by the Tomcat user. If such a package is imported, this will result in sensitive content disclose, including retrieving arbitrary files or configurations from the server where DSpace is running. The Simple Archive Format (SAF) importer / Batch Import (Zip) is only usable by site administrators (from user interface / REST API) or system administrators (from command-line). Therefore, to exploit this vulnerability, the malicious payload would have to be prov

EPSS

Процентиль: 12%
0.00039
Низкий

5.2 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.2
github
7 месяцев назад

DSpace is vulnerable to Path Traversal attacks when importing packages using Simple Archive Format

EPSS

Процентиль: 12%
0.00039
Низкий

5.2 Medium

CVSS3

Дефекты

CWE-22