I can’t speak to DSpace-CRIS 5.10, but that’s a vague message from the IT dept. I would suggest going back to them and asking for more details. A good auditor will document how they exploited the vulnerability, so that you can fix it.
David Cook
Software Engineer
Prosentient Systems
72/330 Wattle St
Ultimo, NSW 2007
Australia
Office: 02 9212 0899
Online: 02 8005 0595
--
All messages to this mailing list should adhere to the DuraSpace Code of Conduct: https://duraspace.org/about/policies/code-of-conduct/
---
You received this message because you are subscribed to the Google Groups "DSpace Technical Support" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dspace-tech...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dspace-tech/CA%2BxAuhPWr8AO5xqkkTE1SbzXK%3D6xuswSS%2BmmfBPoj9OH3s0w4g%40mail.gmail.com.
Without more information from your IT dept and the auditor, you would have to guess at this one at any field that allows user input.
Although someone more familiar with DSpace CRIS might have more information.
Another thing you can try is looking at issue trackers. I don’t see anything at the DSpace CRIS tracker https://github.com/4Science/DSpace/issues, and I don’t see anything obvious when searching the DSpace issue tracker: https://jira.lyrasis.org/projects/DS/issues.
David Cook
Software Engineer
Prosentient Systems
72/330 Wattle St
Ultimo, NSW 2007
Australia
Office: 02 9212 0899
Online: 02 8005 0595
From: dspac...@googlegroups.com <dspac...@googlegroups.com> On Behalf Of Sean Carte
Sent: Wednesday, 21 October 2020 5:38 AM
To: DSpace Technical Support <dspac...@googlegroups.com>
--
All messages to this mailing list should adhere to the DuraSpace Code of Conduct: https://duraspace.org/about/policies/code-of-conduct/
---
You received this message because you are subscribed to the Google Groups "DSpace Technical Support" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dspace-tech...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dspace-tech/CA%2BxAuhPQ9-Bq4agJASMvekOho7rgtokLk4C3DQgLq1Jr%3Dy1O%3DA%40mail.gmail.com.
in any case, I think that information about vulnerabilities must
be keep off the public lists,... the "group" has mechanisms to
deal with these issues.
--
All messages to this mailing list should adhere to the DuraSpace Code of Conduct: https://duraspace.org/about/policies/code-of-conduct/
---
You received this message because you are subscribed to the Google Groups "DSpace Technical Support" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dspace-tech...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dspace-tech/CA%2BxAuhPWr8AO5xqkkTE1SbzXK%3D6xuswSS%2BmmfBPoj9OH3s0w4g%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dspace-tech/DM5PR2201MB1148B556D17188670CF03876ED1C0%40DM5PR2201MB1148.namprd22.prod.outlook.com.
Dear Sean,
We would be interested in the outcome of this, as we have a DSpace CRIS system about to be released.
Kind regards
Marc
To view this discussion on the web visit https://groups.google.com/d/msgid/dspace-tech/CA%2BxAuhNt4-3_HUofq6Ahn_AMS9O81Ddv5h0DB6dgObhSvw0rnA%40mail.gmail.com.
--
Questo messaggio e' stato analizzato da Libra ESVA ed e' risultato non infetto.
This message was scanned by Libra ESVA and is believed to be clean.