GHSA-m58q-qq5h-mgqq
Dashboard / Vulnerabilities / GHSA-m58q-qq5h-mgqq
GHSA-m58q-qq5h-mgqq
Summary: Islandora 2.0 before 2.4.1 could allow any user to upload content into a repository
Details: ### Impact This vulnerability would allow any user, regardless of permissions, to upload content into a repository. This affects installations of Islandora core 2.0 or greater. ### Patches Upgrade immediately to the [latest release](https://github.com/Islandora/islandora/releases/tag/2.4.1) of Islandora. ### Workarounds In lieu of an upgrade the [following module](https://github.com/Islandora/islandora_ghsa_route_fix) can be leveraged that will resolve the issue until such a time an upgrade can take place. ### For more information If you have any questions or comments about this advisory: * Open an issue in [Islandora](https://github.com/Islandora/islandora) * Contact [email protected].
References: https://github.com/Islandora/islandora/security/advisories/GHSA-m58q-qq5h-mgqq, https://github.com/Islandora/islandora/commit/573d6878edf057987f1e41e5068de0074573e4c7, https://github.com/Islandora-CLAW/islandora, https://github.com/Islandora/islandora/releases/tag/2.4.1
Affected packages
Package
Name: islandora/islandora
Purl: pkg:composer/islandora/islandora
Affected ranges
Type: ECOSYSTEM
Events:
