Islandora 2.0 before 2.4.1 could allow any user to upload content into a repository
Critical severity
GitHub Reviewed
Published
Jul 21, 2022
in
Islandora/islandora
•
Updated Jan 12, 2023
Description
Published to the GitHub Advisory Database
Jul 21, 2022
Reviewed
Jul 21, 2022
Last updated
Jan 12, 2023
Impact
This vulnerability would allow any user, regardless of permissions, to upload content into a repository. This affects installations of Islandora core 2.0 or greater.
Patches
Upgrade immediately to the latest release of Islandora.
Workarounds
In lieu of an upgrade the following module can be leveraged that will resolve the issue until such a time an upgrade can take place.
For more information
If you have any questions or comments about this advisory:
References