Information Exposure Affecting org.dspace:dspace-xmlui package, versions [4.0,6.4)


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.26% (50th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Information Exposure vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGDSPACE-2965598
  • published2 Aug 2022
  • disclosed2 Aug 2022
  • creditDavid Cavrenne

Introduced: 2 Aug 2022

CVE-2022-31190  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade org.dspace:dspace-xmlui to version 6.4 or higher.

Overview

org.dspace:dspace-xmlui is a web-based user interface based upon Apache Cocoon.

Affected versions of this package are vulnerable to Information Exposure in the generate() functions of cocoon/DSpaceMETSGenerator.java and cocoon/DSpaceOREGenerator.java, which expose metadata on withdrawn items in the mets.xml object. An attacker in possession of the handle/URL of a withdrawn item can retrieve the metadata.

Note: This vulnerability does not impact the JSPUI or versions 7.

CVSS Base Scores

version 3.1