{"id":"GHSA-4m9r-5gqp-7j82","summary":"High severity vulnerability that affects org.dspace:dspace-xmlui","details":"The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack with two or more arbitrary characters and a colon before a pathname, as demonstrated by a themes/Reference/aa:etc/passwd URI.","aliases":["CVE-2016-10726"],"modified":"2023-11-08T03:58:21.266725Z","published":"2018-10-19T16:52:06Z","database_specific":{"cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T20:58:34Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10726"},{"type":"WEB","url":"https://github.com/DSpace/DSpace/releases/tag/dspace-5.5"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4m9r-5gqp-7j82"},{"type":"WEB","url":"https://jira.duraspace.org/browse/DS-3094"},{"type":"WEB","url":"https://wiki.duraspace.org/display/DSDOC5x/Release+Notes"}],"affected":[{"package":{"name":"org.dspace:dspace-xmlui","ecosystem":"Maven","purl":"pkg:maven/org.dspace/dspace-xmlui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0"},{"fixed":"4.5"}]}],"versions":["4.0","4.1","4.2","4.3","4.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-4m9r-5gqp-7j82/GHSA-4m9r-5gqp-7j82.json"}},{"package":{"name":"org.dspace:dspace-xmlui","ecosystem":"Maven","purl":"pkg:maven/org.dspace/dspace-xmlui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0"},{"fixed":"5.5"}]}],"versions":["5.0","5.1","5.2","5.3","5.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-4m9r-5gqp-7j82/GHSA-4m9r-5gqp-7j82.json"}},{"package":{"name":"org.dspace:dspace-xmlui","ecosystem":"Maven","purl":"pkg:maven/org.dspace/dspace-xmlui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6"}]}],"versions":["1.5-alpha","1.5.0","1.5.0-beta1","1.5.0-beta2","1.5.0-rc1","1.5.1","1.5.1-beta","1.5.2","1.5.2-rc1","1.5.2-rc2","1.6.0","1.6.0-rc1","1.6.0-rc2","1.6.1","1.6.2","1.7.0","1.7.0-rc1","1.7.0-rc2","1.7.1","1.7.2","1.7.3","1.8.0","1.8.0-rc1","1.8.0-rc2","1.8.0-rc3","1.8.1","1.8.2","1.8.3","3.0","3.0-rc1","3.0-rc2","3.0-rc3","3.1","3.2","3.3","3.4","3.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-4m9r-5gqp-7j82/GHSA-4m9r-5gqp-7j82.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}