{"id":"GHSA-m58q-qq5h-mgqq","aliases":[],"url":"https://o3.security/vulnerability/GHSA-m58q-qq5h-mgqq","summary":"Islandora 2.0 before 2.4.1 could allow any user to upload content into a repository","details":"### Impact\nThis vulnerability would allow any user, regardless of permissions, to upload content into a repository. This affects installations of Islandora core 2.0 or greater.\n\n### Patches\nUpgrade immediately to the [latest release](https://github.com/Islandora/islandora/releases/tag/2.4.1) of Islandora.\n\n### Workarounds\nIn lieu of an upgrade the [following module](https://github.com/Islandora/islandora_ghsa_route_fix) can be leveraged that will resolve the issue until such a time an upgrade can take place.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [Islandora](https://github.com/Islandora/islandora)\n* Contact community@islandora.ca.\n","published":"2022-07-21T22:36:20Z","modified":"2024-11-28T05:44:01.860547Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"islandora/islandora","fixedVersion":"2.4.1"}],"fix":{"url":"https://github.com/Islandora/islandora/commit/573d6878edf057987f1e41e5068de0074573e4c7","label":"Islandora/islandora@573d687"},"references":[{"type":"WEB","url":"https://github.com/Islandora/islandora/security/advisories/GHSA-m58q-qq5h-mgqq"},{"type":"WEB","url":"https://github.com/Islandora/islandora/commit/573d6878edf057987f1e41e5068de0074573e4c7"},{"type":"PACKAGE","url":"https://github.com/Islandora-CLAW/islandora"},{"type":"WEB","url":"https://github.com/Islandora/islandora/releases/tag/2.4.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-28T05:44:01.860547Z"}}