{"id":"GHSA-m58q-qq5h-mgqq","summary":"Islandora 2.0 before 2.4.1 could allow any user to upload content into a repository","details":"### Impact\nThis vulnerability would allow any user, regardless of permissions, to upload content into a repository. This affects installations of Islandora core 2.0 or greater.\n\n### Patches\nUpgrade immediately to the [latest release](https://github.com/Islandora/islandora/releases/tag/2.4.1) of Islandora.\n\n### Workarounds\nIn lieu of an upgrade the [following module](https://github.com/Islandora/islandora_ghsa_route_fix) can be leveraged that will resolve the issue until such a time an upgrade can take place.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [Islandora](https://github.com/Islandora/islandora)\n* Contact community@islandora.ca.\n","modified":"2024-11-28T05:46:13.804130Z","published":"2022-07-21T22:36:20Z","database_specific":{"github_reviewed_at":"2022-07-21T22:36:20Z","nvd_published_at":null,"cwe_ids":[],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/Islandora/islandora/security/advisories/GHSA-m58q-qq5h-mgqq"},{"type":"WEB","url":"https://github.com/Islandora/islandora/commit/573d6878edf057987f1e41e5068de0074573e4c7"},{"type":"PACKAGE","url":"https://github.com/Islandora-CLAW/islandora"},{"type":"WEB","url":"https://github.com/Islandora/islandora/releases/tag/2.4.1"}],"affected":[{"package":{"name":"islandora/islandora","ecosystem":"Packagist","purl":"pkg:composer/islandora/islandora"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0"},{"fixed":"2.4.1"}]}],"versions":["2.0.0","2.0.1","2.1.0","2.1.1","2.2.0","2.2.1","2.3.0","2.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-m58q-qq5h-mgqq/GHSA-m58q-qq5h-mgqq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}