Lucene search

K
cvelistGitHub_MCVELIST:CVE-2021-41189
HistoryOct 29, 2021 - 5:25 p.m.

CVE-2021-41189 Communities and collections administrators can escalate their privilege up to system administrator

2021-10-2917:25:10
CWE-863
GitHub_M
www.cve.org

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.004 Low

EPSS

Percentile

72.6%

DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up to become system administrator. This vulnerability only exists in 7.0 and does not impact 6.x or below. This issue is patched in version 7.1. As a workaround, users of 7.0 may temporarily disable the ability for community or collection administrators to manage permissions or workflows settings.

CNA Affected

[
  {
    "product": "DSpace",
    "vendor": "DSpace",
    "versions": [
      {
        "status": "affected",
        "version": ">= 7.0, < 7.1"
      }
    ]
  }
]

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.004 Low

EPSS

Percentile

72.6%

Related for CVELIST:CVE-2021-41189