Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Table of Contents
minLevel2
outlinetrue
stylenone

Warning

Support for DSpace 5 ended on January 1, 2023.  See Support for DSpace 5 and 6 is ending in 2023


Tip
titleDSpace 5.6 was officially released to the public on September 29, 2016.

DSpace 5.6 can be downloaded immediately from:

More information on the 5.6 release (and the 5.x platform in general) can be found in the 5.x Release Notes

Upgrade instructions can be found at Upgrading DSpace.

...

Major bug fixes include:

  • JSPUI, XMLUI, REST security fixes:
    • JSPUI and XMLUI
      •  [HIGH MEDIUM SEVERITY]  XML External Entity (XXE) vulnerability in pdfbox. (DS-3309 - requires a JIRA account to access)
        • Reported by Seth Robbins  
    • JSPUI, XMLUI and REST
      • [HIGH MEDIUM SEVERITY]  Bitstreams of embargoed and/or withdrawn items can be accessed by anyone. (DS-3097 - requires a JIRA account to access)
        • Reported by Franziska Ackermann
  • JSPUI security fix:
  • REST security fix:
    • [HIGH SEVERITY]  SQL Injection Vulnerability in 5.x REST API (DS-3250 - requires a JIRA account to access)
  • JSPUI bug fixes:Other minor fixes and improvements
    • JSPUI: Creative Commons license fails with fetch directy the url (instead use the Creative Commons REST API) (DS-2604)
    • JSPUI: Upload a file, multifile, with a description text during the submission process (DS-2623)
    • JSPUI: Bug fix to EPerson popup (DS-2968)
  • XMLUI bug fixes:
    • XMLUI: Recyclable Cocoon components should clear local variables (DS-3246)  
    • XMLUI: "Request a copy" feature was not working when the property request.item-type was set to all ( DS-3294)
    • XMLUI: Bug fix to policy search form (DS-3206)
  • Other minor fixes and improvements
    • METSRightsCrosswalk NPE During AIP Restore - No Anonymous Read (DS-3140)

    • AIP Restore is not respecting access restrictions (on Items) (DS-3266)

    • Error when missing Context Description in xoai.xml (DS-2874)
    • Bug fix to REST API 'find-by-metadata-field' (DS-3248)

In addition, this release fixes a variety of minor bugs in the 5.x releases. For more information, see the Changes section below.

...