Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

This release addresses the following security issues discovered in DSpace 4.x and below:

  •  JSPUI security fix:JSPUI, XMLUI, REST security fixfixes:
    • JSPUI and XMLUI
      •  [
      HIGH
      • MEDIUM SEVERITY]  XML External Entity (XXE) vulnerability in pdfbox. (DS-3309 - requires a JIRA account to access)
       
      • (NOTE: this ticket was actually fixed in an earlier, unannounced 4.6 release, but it is also included in 4.7)
        • Reported by Seth Robbins
       
    • JSPUI, XMLUI and REST
      • [MEDIUM SEVERITY]
      Bitstreams
      •   Bitstreams of embargoed and/or withdrawn items can be accessed by
      anyone 
      • anyone. (DS-3097 - requires a JIRA account to access)
        • Reported by Franziska Ackermann
  • JSPUI security fix:
    • [HIGH SEVERITY]  Any registered user can modify inprogress submission. (DS-2895 - requires a JIRA account to access
     

Upgrade Instructions

...