CVE-2021-41189

Source
https://cve.org/CVERecord?id=CVE-2021-41189
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41189.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-41189
Aliases
Published
2021-10-29T18:15:08.167Z
Modified
2026-07-22T03:45:00.005769Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up to become system administrator. This vulnerability only exists in 7.0 and does not impact 6.x or below. This issue is patched in version 7.1. As a workaround, users of 7.0 may temporarily disable the ability for community or collection administrators to manage permissions or workflows settings.

References

Affected packages

Git / github.com/dspace/dspace

Affected ranges

Type
GIT
Repo
https://github.com/dspace/dspace
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "7.0"
        },
        {
            "last_affected": "7.0"
        }
    ],
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:duraspace:dspace:7.0:*:*:*:*:*:*:*"
}

Affected versions

7.*
7.0
dspace-7.*
dspace-7.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41189.json"
vanir_signatures
[
    {
        "target": {
            "function": "getParentObject",
            "file": "dspace-api/src/main/java/org/dspace/eperson/GroupServiceImpl.java"
        },
        "deprecated": false,
        "source": "https://github.com/dspace/dspace/commit/277b499a5cd3a4f5eb2370513a1b7e4ec2a6e041",
        "id": "CVE-2021-41189-785133fb",
        "signature_version": "v1",
        "digest": {
            "length": 2175.0,
            "function_hash": "300703942850089325555200617024825898010"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "dspace-api/src/main/java/org/dspace/content/service/CollectionService.java"
        },
        "deprecated": false,
        "source": "https://github.com/dspace/dspace/commit/277b499a5cd3a4f5eb2370513a1b7e4ec2a6e041",
        "id": "CVE-2021-41189-820fbed8",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "230798946752315261717296430345997332043",
                "13401686154371968592278051498363089820",
                "307591327053913332370648358526800182460"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "dspace-api/src/main/java/org/dspace/eperson/GroupServiceImpl.java"
        },
        "deprecated": false,
        "source": "https://github.com/dspace/dspace/commit/277b499a5cd3a4f5eb2370513a1b7e4ec2a6e041",
        "id": "CVE-2021-41189-a7ca2087",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "209249221542853587669291702545322422978",
                "126126519311340262262335053028203607459",
                "282385326733389899354576746093800232735",
                "84414299395832729929759351299940169504",
                "85112930840899592341259373024136118099",
                "139788679936160346317096787640791413104",
                "241571774435735182719182461947301654296",
                "295230699130811921549902199895576357548",
                "117700386491633210932920169666002962599",
                "12032035476877785544352715591560403214",
                "284124523467711487177343576106756151038",
                "239724670870282889366623249644829619574",
                "322647976281609410706189750777180941865",
                "29376380940439398493533603112876556022"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "dspace-api/src/main/java/org/dspace/content/CollectionServiceImpl.java"
        },
        "deprecated": false,
        "source": "https://github.com/dspace/dspace/commit/277b499a5cd3a4f5eb2370513a1b7e4ec2a6e041",
        "id": "CVE-2021-41189-c7ea9560",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "196826502245016391686280800340631035976",
                "171770372963899684885264282570822818221",
                "197871904666286928465267506081521490159",
                "161670904239402850784274582125300460895",
                "216067711973397635315824259312731716698",
                "278782392596734839312796171824750082758",
                "302221001954456206374792079686453314356",
                "63605672418722836566913855809091547469"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "createDefaultReadGroup",
            "file": "dspace-api/src/main/java/org/dspace/content/CollectionServiceImpl.java"
        },
        "deprecated": false,
        "source": "https://github.com/dspace/dspace/commit/277b499a5cd3a4f5eb2370513a1b7e4ec2a6e041",
        "id": "CVE-2021-41189-d2561338",
        "signature_version": "v1",
        "digest": {
            "length": 458.0,
            "function_hash": "289300671921869405454201827268937939277"
        },
        "signature_type": "Function"
    }
]
vanir_signatures_modified
"2026-07-22T03:45:00Z"