cvedb.io
CVE-2022-31190
MEDIUM · CVSS 5.3
EPSS exploitation probability: 0%
Published 2022-08-01T20:15:08.707 · Last modified 2026-06-17T04:44:59.797

Summary

DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace. In affected versions metadata on a withdrawn Item is exposed via the XMLUI "mets.xml" object, as long as you know the handle/URL of the withdrawn Item. This vulnerability only impacts the XMLUI. Users are advised to upgrade to version 6.4 or newer.

Affected products

duraspace — dspace

Does this affect you?

Add your gear to cvedb and we'll alert you only when duraspace ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.