DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace. In affected versions metadata on a withdrawn Item is exposed via the XMLUI "mets.xml" object, as long as you know the handle/URL of the withdrawn Item. This vulnerability only impacts the XMLUI. Users are advised to upgrade to version 6.4 or newer.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.dspace:dspace-xmlui(Maven) | 4.0 | 6.4 | N/A |
CVSS Metrics