Lucene search

K
cve[email protected]CVE-2022-31189
HistoryAug 01, 2022 - 9:15 p.m.

CVE-2022-31189

2022-08-0121:15:13
CWE-209
web.nvd.nist.gov
51
3
cve-2022-31189
dspace
open source
software
repository
application
dspace-jspui
ui component
vulnerability
internal system error
stack trace
attacker
security
upgrade
nvd

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

26.4%

DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. When an “Internal System Error” occurs in the JSPUI, then entire exception (including stack trace) is available. Information in this stacktrace may be useful to an attacker in launching a more sophisticated attack. This vulnerability only impacts the JSPUI. This issue has been fixed in version 6.4. users are advised to upgrade. Users unable to upgrade should disable the display of error messages in their internal.jsp file.

Affected configurations

Vulners
NVD
Node
dspacedspaceRange4.06.4
CPENameOperatorVersion
duraspace:dspaceduraspace dspacelt6.4

CNA Affected

[
  {
    "product": "DSpace",
    "vendor": "DSpace",
    "versions": [
      {
        "status": "affected",
        "version": ">= 4.0, < 6.4"
      }
    ]
  }
]

Social References

More

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

26.4%

Related for CVE-2022-31189