Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

This release addresses the following security issues discovered in DSpace 4.x and below:

DSpace JSPUI security fixes:

  • [HIGH SEVERITY] A user can inject malicious Javascript into the names of EPeople or Groups. This is most severe in sites which allow anyone to register for a new account. (https://jira.duraspace.org/browse/DS-3866 - requires a JIRA account to access.) 

    • Reported by Julio Brafman

  • [MEDIUM SEVERITY] Any user was able to export metadata to CSV format if they knew the correct JSPUI path/parameters. Additionally, the exported CSV included metadata fields which are flagged as hidden in configuration. (https://jira.duraspace.org/browse/DS-3840 - requires a JIRA account to access.) 

    • Reported by Eike Kleiner (ZHAW, Zurich University of Applied Sciences)

In addition, this release fixes a few minor bugs in the 4.x releases. For more information, see the Changes section below.

...