{"id":"CVE-2021-41189","details":"DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up to become system administrator. This vulnerability only exists in 7.0 and does not impact 6.x or below. This issue is patched in version 7.1. As a workaround, users of 7.0 may temporarily disable the ability for community or collection administrators to manage permissions or workflows settings.","aliases":["GHSA-cf2j-vf36-c6w8"],"modified":"2026-07-22T03:45:00.005769Z","published":"2021-10-29T18:15:08.167Z","references":[{"type":"ADVISORY","url":"https://github.com/DSpace/DSpace/security/advisories/GHSA-cf2j-vf36-c6w8"},{"type":"FIX","url":"https://github.com/DSpace/DSpace/commit/277b499a5cd3a4f5eb2370513a1b7e4ec2a6e041"},{"type":"FIX","url":"https://github.com/DSpace/DSpace/commit/c3bea16ab911606e15ae96c97a1575e1ffb14f8a"},{"type":"EVIDENCE","url":"https://github.com/DSpace/DSpace/issues/7928"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dspace/dspace","events":[{"introduced":"69345ff3fce834d45d0571a340b286b2777ecf49"},{"last_affected":"69345ff3fce834d45d0571a340b286b2777ecf49"},{"fixed":"277b499a5cd3a4f5eb2370513a1b7e4ec2a6e041"},{"fixed":"c3bea16ab911606e15ae96c97a1575e1ffb14f8a"}],"database_specific":{"cpe":"cpe:2.3:a:duraspace:dspace:7.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["7.0","dspace-7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41189.json","vanir_signatures_modified":"2026-07-22T03:45:00Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"300703942850089325555200617024825898010","length":2175},"id":"CVE-2021-41189-785133fb","signature_type":"Function","signature_version":"v1","source":"https://github.com/dspace/dspace/commit/277b499a5cd3a4f5eb2370513a1b7e4ec2a6e041","target":{"file":"dspace-api/src/main/java/org/dspace/eperson/GroupServiceImpl.java","function":"getParentObject"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/dspace/dspace/commit/277b499a5cd3a4f5eb2370513a1b7e4ec2a6e041","target":{"file":"dspace-api/src/main/java/org/dspace/content/service/CollectionService.java"},"deprecated":false,"digest":{"line_hashes":["230798946752315261717296430345997332043","13401686154371968592278051498363089820","307591327053913332370648358526800182460"],"threshold":0.9},"id":"CVE-2021-41189-820fbed8"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/dspace/dspace/commit/277b499a5cd3a4f5eb2370513a1b7e4ec2a6e041","target":{"file":"dspace-api/src/main/java/org/dspace/eperson/GroupServiceImpl.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["209249221542853587669291702545322422978","126126519311340262262335053028203607459","282385326733389899354576746093800232735","84414299395832729929759351299940169504","85112930840899592341259373024136118099","139788679936160346317096787640791413104","241571774435735182719182461947301654296","295230699130811921549902199895576357548","117700386491633210932920169666002962599","12032035476877785544352715591560403214","284124523467711487177343576106756151038","239724670870282889366623249644829619574","322647976281609410706189750777180941865","29376380940439398493533603112876556022"]},"id":"CVE-2021-41189-a7ca2087"},{"signature_version":"v1","source":"https://github.com/dspace/dspace/commit/277b499a5cd3a4f5eb2370513a1b7e4ec2a6e041","target":{"file":"dspace-api/src/main/java/org/dspace/content/CollectionServiceImpl.java"},"deprecated":false,"digest":{"line_hashes":["196826502245016391686280800340631035976","171770372963899684885264282570822818221","197871904666286928465267506081521490159","161670904239402850784274582125300460895","216067711973397635315824259312731716698","278782392596734839312796171824750082758","302221001954456206374792079686453314356","63605672418722836566913855809091547469"],"threshold":0.9},"id":"CVE-2021-41189-c7ea9560","signature_type":"Line"},{"deprecated":false,"digest":{"function_hash":"289300671921869405454201827268937939277","length":458},"id":"CVE-2021-41189-d2561338","signature_type":"Function","signature_version":"v1","source":"https://github.com/dspace/dspace/commit/277b499a5cd3a4f5eb2370513a1b7e4ec2a6e041","target":{"file":"dspace-api/src/main/java/org/dspace/content/CollectionServiceImpl.java","function":"createDefaultReadGroup"}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}