[dspace-devel] Re: NOTICE: DSpace 7 is impacted by new "Spring4Shell" zero-day vulnerability. Does not impact DSpace 6 or below.

2022-04-01 Thread 'Tim Donohue' via DSpace Developers
All, The DSpace 7.2.1 release of the backend is also now available. This is a quick upgrade for any sites already running 7.2. https://github.com/DSpace/DSpace/releases/tag/dspace-7.2.1 For the latest information on how to protect your site against Spring4Shell (CVE-2022-22965), see the list

[dspace-devel] NOTICE: DSpace 7 is impacted by new "Spring4Shell" zero-day vulnerability. Does not impact DSpace 6 or below.

2022-04-01 Thread 'Tim Donohue' via DSpace Developers
All, You may have heard or been notified about a new significant vulnerability in the Java Spring Framework nicknamed Spring4Shell (CVE-2022-22965): https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement DSpace 7 is impacted by this vulnerability provided that you are running