github DSpace/DSpace dspace-7.1.1
DSpace 7.1.1 (Backend / REST API Only)

latest releases: dspace-7.6.2, dspace-8.0, dspace-8.0-rc1...
2 years ago

This is an updated version of the 7.1 release which includes a security update for CVE-2021-44228 (log4j v2 critical vulnerability). It is fully compatible with the DSpace 7 Frontend dspace-7.1 release.


⚠️ We highly recommend ALL users of DSpace 7.0 or 7.1 upgrade to 7.1.1 (or above) to resolve CVE-2021-44228.

To fully protect your DSpace 7.x site from CVE-2021-44228, three steps are required:

  1. Upgrade your DSpace backend to 7.1.1 (or above) OR manually install #8065, rebuild and redeploy your 7.x backend. Make sure to restart your Tomcat after the update.
  2. Upgrade to Apache Solr v8.11.1 (or above), OR ensure that -Dlog4j2.formatMsgNoLookups=true is specified in your SOLR_OPTS environment variable. For more information, see https://solr.apache.org/security.html#apache-solr-affected-by-apache-log4j-cve-2021-44228
  3. If you use the Handle.Net Registry Support in DSpace 7.x, make sure to restart your Handle Server (after performing step 1), so that it uses the new (secure) version of log4j as well.

This DSpace Backend does not have a user friendly interface. Therefore, we highly recommend installing the DSpace 7 Frontend dspace-7.1 release to use with this Backend. Please note that the Frontend and Backend do not need to be installed on the same machine. (Note: it is also possible to run this Backend "headless" if you only want to use the DSpace REST API)

Download links for the Backend are available below (see Assets). You may alternatively choose to checkout the code via GitHub, using the dspace-7.1.1 tag.

Additional Information on the 7.1 release:

Full Changelog of 7.1.1: dspace-7.1...dspace-7.1.1

Don't miss a new DSpace release

NewReleases is sending notifications on new releases.