GHSA-8rmh-55h4-93h5
HIGHCVE-2022-31195ItemImportServiceImpl is vulnerable to a path traversal vulnerability. This means a malicious SAF (simple archive format) package could cause a file/directory to be created anywhere the Tomcat/DSpace user can write to on the server. However, this path traversal vulnerability is only possible by a user with special privileges (either Administrators or someone with command-line access to the server
- Affected
- >= 6.0, < 6.4
- Fixed in
- 6.4
- Published
- 2022-08-06
- Source
- github