Lucene search

K
osvGoogleOSV:GHSA-4M9R-5GQP-7J82
HistoryOct 19, 2018 - 4:52 p.m.

High severity vulnerability that affects org.dspace:dspace-xmlui

2018-10-1916:52:06
Google
osv.dev
10

0.002 Low

EPSS

Percentile

58.5%

The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack with two or more arbitrary characters and a colon before a pathname, as demonstrated by a themes/Reference/aa:etc/passwd URI.

0.002 Low

EPSS

Percentile

58.5%

Related for OSV:GHSA-4M9R-5GQP-7J82