Skip to content

[Port dspace-9_x] Fix CVE-2025-53621 by improving SAF Import XML handling #11035

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 6 commits into from
Jul 14, 2025

Conversation

kshepherd
Copy link
Member

@kshepherd kshepherd commented Jul 14, 2025

Manual backport of #11030 to dspace-9_x branch (for 9.x sites). See that ticket for details.

@kshepherd kshepherd requested a review from tdonohue July 14, 2025 14:28
@kshepherd kshepherd self-assigned this Jul 14, 2025
@kshepherd kshepherd changed the title Improve SAF Import XML handling (7.x) Improve SAF Import XML handling (9.x) Jul 14, 2025
@tdonohue tdonohue added bug high priority tools: import Related to import of data into the system tools: import-sources Related to "Live Import" Sources feature, allowing import of content via external APIs. labels Jul 14, 2025
@tdonohue tdonohue added this to the 9.1 milestone Jul 14, 2025
@tdonohue tdonohue marked this pull request as ready for review July 14, 2025 15:03
@tdonohue tdonohue merged commit 28b5f38 into DSpace:dspace-9_x Jul 14, 2025
30 checks passed
@github-project-automation github-project-automation bot moved this from 👍 Reviewer Approved to ✅ Done in DSpace Maintenance (9.x, 8.x, 7.6.x) Jul 14, 2025
@tdonohue tdonohue changed the title Improve SAF Import XML handling (9.x) [Port dspace-9_x] Fix CVE-2025-53621 by improving SAF Import XML handling Jul 15, 2025
@tdonohue tdonohue added the security Security related fix label Jul 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug high priority security Security related fix tools: import Related to import of data into the system tools: import-sources Related to "Live Import" Sources feature, allowing import of content via external APIs.
Projects
Development

Successfully merging this pull request may close these issues.

2 participants