DSpace 开源软件是一个提供数字资源持久访问功能的仓储应用程序。在版本 8.0-rc1 至 8.4 之前、9.0-rc1 至 9.3 之前,以及 10-rc1 版本中,攻击者可以通过 DSpace 用于处理 COAR Notify/LDN 消息的 Velocity 模板实现远程代码执行(RCE)。该问题已在版本 8.4、9.3 和 10.0 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49833 | 5.5 MEDIUM | DSpace: Path Traversal possible in LDN message generation |
| CVE-2026-49831 | 5.5 MEDIUM | DSpace: Curation Task Reporter output path is not restricted to trusted directories (Path |
| CVE-2026-49830 | 4.4 MEDIUM | DSpace: ORE resource URI does not validate scheme for non-web resources |
No comments yet