Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  •  JSPUI security fix:
  • JSPUI, XMLUI, REST security fix:
    • [HIGH SEVERITY] XML External Entity (XXE) vulnerability in pdfbox. (DS-3309 - requires a JIRA account to access)  (NOTE: this ticket was actually fixed in an earlier, unannounced 4.6 release, but it is also included in 4.7)
      • Reported by Seth Robbins
       
    • [MEDIUM SEVERITY] Bitstreams of embargoed and/or withdrawn items can be accessed by anyone (DS-3097 - requires a JIRA account to access)
      • Reported by Franziska Ackermann
     

Upgrade Instructions

...

Note

4.7 is a security-fix release. This means it includes no new features and only includes the above listed security fixes.

For a list of all new 4.x Features, please visit the 4.x Release Notes.

...