Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

This release addresses the following security issues discovered in DSpace 4.x and below:

  •  JSPUI, XMLUI, REST security fixfixes:
    • JSPUI and XMLUI
      •  [MEDIUM SEVERITY] 
      Any registered user can modify inprogress submission
      • XML External Entity (XXE) vulnerability in pdfbox. (DS-
      2895
      • 3309 - requires a JIRA account to access) (NOTE: this ticket was actually fixed in an earlier, unannounced 4.6 release, but it is also included in 4.7)
        • Reported by
        Andrea Bollini (4Science)
        • Seth Robbins
    • JSPUI, XMLUI
    , :
    • and REST
    security fix

      • [MEDIUM SEVERITY]
      Bitstreams
      •   Bitstreams of embargoed and/or withdrawn items can be accessed by
      anyone 
      • anyone. (DS-3097 - requires a JIRA account to access)
        • Reported by Franziska Ackermann
  • JSPUI security fix:
    • [HIGH SEVERITY]  Any registered user can modify inprogress submission. (DS-2895 - requires a JIRA account to access
     

Upgrade Instructions

...

Note

4.7 is a security-fix release. This means it includes no new features and only includes the above listed security fixes.

For a list of all new 4.x Features, please visit the 4.x Release Notes.

...