DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI controlled vocabulary servlet is vulnerable to an open redirect attack, where an attacker can craft a malicious URL that looks like a legitimate DSpace/repository URL. When that URL is clicked by the target, it redirects them to a site of the attacker's choice. This issue has been patched in versions 5.11 and 6.4. Users are advised to upgrade. There are no known workaround for this vulnerability.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-08-01T20:25:12
Updated: 2024-08-03T07:11:39.618Z
Reserved: 2022-05-18T00:00:00
Link: CVE-2022-31193
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-08-01T21:15:13.423
Modified: 2024-11-21T07:04:05.747
Link: CVE-2022-31193
Redhat
No data.