<html><head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
  </head>
  <body>
    <p>I would definitely use mathjax over the cgi route. <br>
    </p>
    <p><br>
    </p>
    <p>Our server has the js added to&nbsp; cfg/lang/en/templates/default.xml
      <br>
    </p>
    <pre class="code highlight" lang="xml"><span id="LC3" class="line hll" lang="xml"> <span class="nt">&lt;script</span> <span class="na">type=</span><span class="s">&quot;text/x-mathjax-config&quot;</span><span class="nt">&gt;</span></span>
<span id="LC4" class="line hll" lang="xml">    MathJax.Hub.Config({tex2jax: {inlineMath: [['$','$'], ['\\(','\\)']]}});</span>
<span id="LC5" class="line" lang="xml">  <span class="nt">&lt;/script&gt;</span></span>
<span id="LC6" class="line" lang="xml">  <span class="nt">&lt;script</span> <span class="na">type=</span><span class="s">&quot;text/javascript&quot;</span> <span class="na">async=</span><span class="s">&quot;async&quot;</span></span>
<span id="LC7" class="line hll" lang="xml">    <span class="na">src=</span><span class="s"><a class="moz-txt-link-rfc2396E" href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcdnjs.cloudflare.com%2Fajax%2Flibs%2Fmathjax%2F2.7.1%2FMathJax.js%3Fconfig%3DTeX-MML-AM_CHTML&amp;data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C8345e1db2f4f4bef1e4008d8d8d666de%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637497762657466557%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=c%2B6xiBNDk6toAIBQDNio6DdLjzFueC9SrBHBEQwF30w%3D&amp;reserved=0" originalSrc="https://cdnjs.cloudflare.com/ajax/libs/mathjax/2.7.1/MathJax.js?config=TeX-MML-AM_CHTML" shash="eiEAIgdOYf5F6/u3ammGjIJQLv5rAZMHjCRiOwKFX7OgMM31bLBnXoqIPR5rMnAqiOCXL1Q74glfPx9ekhyi7FBMKYrust6JALoLp5MZTvDB+8GxNDt8gxuok+PgRS6OgWL9PDzQrHL6umJYA382csEuKF0Hy+uGBeyOZnyOlPM=">&quot;https://cdnjs.cloudflare.com/ajax/libs/mathjax/2.7.1/MathJax.js?config=TeX-MML-AM_CHTML&quot;</a></span><span class="nt">&gt;</span></span>
<span id="LC8" class="line" lang="xml">  <span class="nt">&lt;/script&gt;

</span></span>And nothing else. Maybe that's enough to get it to work? 
</pre>
    <p><br>
    </p>
    <div class="moz-cite-prefix">On 24/02/2021 14:35, John Salter via
      Eprints-tech wrote:<br>
    </div>
    <blockquote type="cite" cite="mid:EMEW3|5eec185edca14c6263946f14f899f16ax1NErc14eprints-tech-bounces|ecs.soton.ac.uk|DB6PR0301MB256552CAA538817B0FC75625C49F9@DB6PR0301MB2565.eurprd03.prod.outlook.com">
      
      <style type="text/css" style="display:none;">P {margin-top:0;margin-bottom:0;}</style>
      <div style="padding-bottom: 10px; padding-top: 5px;">
        <div style="padding:12px; border:1px solid #8D3970;
          background-color:#F7F9FA; color:#8D3970; font-size:14px;
          line-height:22px; font-family: Calibri, Arial, Helvetica,
          sans-serif;">
          <strong>CAUTION:</strong> This e-mail originated outside the
          University of Southampton.
        </div>
      </div>
      <div>
        <div style="font-family: Calibri, Arial, Helvetica, sans-serif;
          font-size: 12pt; color: rgb(0, 0, 0);">
          I was wondering if anyone had integrated any javascript
          libraries (e.g.&nbsp;<a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.mathjax.org%2F&amp;data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C8345e1db2f4f4bef1e4008d8d8d666de%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637497762657466557%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=JoWfryx%2FUTJdiva388sGySYo%2Fncf3SAlyu8txCRzCxk%3D&amp;reserved=0" originalSrc="https://www.mathjax.org/" shash="b2iEfbUnvRiiRICkvsWqF1wjSP96TspPlFB19mOQ/lsVfaVWxjSg6wR3a+Go9IW3mvYlvo15DCVPJbXmI6moRRw3q8DJbmY005TXloYO718CDFJ80oPNMcXGKQY4G2TBGhyku6NWzm//WDa7PMjuh4UplBhZoqVr+67hvaapyos=" originalsrc="https://www.mathjax.org/" shash="JKmujr107icELDrLG/m/A8PfZ6eKrgJGfQ7g/U4+rim8IBmnRH11KvtIase9ASH/878d5LE2iNE+OzXgnx2ugYWtgq9PC/LI5e3dmMSuLMztc1mk+kJ+4KGmbCi0qLXKydkmXMl4fQbna23PH3PfDJZ4x3zPqyYZwPNCzFHNP/c=" id="LPlnk" moz-do-not-send="true">https://www.mathjax.org/</a>)&nbsp;to
          achieve something similar to this?<br>
          <br>
          Cheers,</div>
        <div style="font-family: Calibri, Arial, Helvetica, sans-serif;
          font-size: 12pt; color: rgb(0, 0, 0);">
          John</div>
        <hr style="display:inline-block;width:98%" tabindex="-1">
        <div id="divRplyFwdMsg" dir="ltr"><font style="font-size:11pt" face="Calibri, sans-serif" color="#000000"><b>From:</b>
            <a class="moz-txt-link-abbreviated" href="mailto:eprints-tech-bounces@ecs.soton.ac.uk">eprints-tech-bounces@ecs.soton.ac.uk</a>
            <a class="moz-txt-link-rfc2396E" href="mailto:eprints-tech-bounces@ecs.soton.ac.uk">&lt;eprints-tech-bounces@ecs.soton.ac.uk&gt;</a> on behalf of
            Alan.Stiles via Eprints-tech
            <a class="moz-txt-link-rfc2396E" href="mailto:eprints-tech@ecs.soton.ac.uk">&lt;eprints-tech@ecs.soton.ac.uk&gt;</a><br>
            <b>Sent:</b> 24 February 2021 14:03<br>
            <b>To:</b> <a class="moz-txt-link-abbreviated" href="mailto:eprints-tech@ecs.soton.ac.uk">eprints-tech@ecs.soton.ac.uk</a>
            <a class="moz-txt-link-rfc2396E" href="mailto:eprints-tech@ecs.soton.ac.uk">&lt;eprints-tech@ecs.soton.ac.uk&gt;</a><br>
            <b>Subject:</b> Re: [EP-tech] EPrints Security Announcement
            - February 2020</font>
          <div>&nbsp;</div>
        </div>
        <style>@font-face
        {font-family:"Cambria Math"}@font-face
        {font-family:Calibri}p.x_MsoNormal, li.x_MsoNormal, div.x_MsoNormal
        {margin:0cm;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif}a:link, span.x_MsoHyperlink
        {color:blue;
        text-decoration:underline}span.x_EmailStyle20
        {font-family:"Calibri",sans-serif;
        color:windowtext}.x_MsoChpDefault
        {font-size:10.0pt}div.x_WordSection1
        {}</style>
        <div link="blue" vlink="purple" style="word-wrap:break-word" lang="EN-GB">
          <div style="padding-bottom:10px; padding-top:5px">
            <div style="padding:12px; border:1px solid #8D3970;
              background-color:#F7F9FA; color:#8D3970; font-size:14px;
              line-height:22px;
              font-family:Calibri,Arial,Helvetica,sans-serif">
              <strong>CAUTION:</strong> This e-mail originated outside
              the University of Southampton.
            </div>
          </div>
          <div>
            <div class="x_WordSection1">
              <p class="x_MsoNormal"><span style="">The patch does leave
                  latex2png empty.</span></p>
              <p class="x_MsoNormal"><span style="">We still use this to
                  include e.g. mathematical symbology in item abstracts
                  so we have added some sanitisation to the input
                  parameter in that cgi script rather than removing the
                  function completely (3.3.15 or 16 here).</span></p>
              <p class="x_MsoNormal"><span style="">&nbsp;</span></p>
              <p class="x_MsoNormal"><span style="">Alan</span></p>
              <p class="x_MsoNormal"><span style="">&nbsp;</span></p>
              <div style="border:none; border-top:solid #B5C4DF 1.0pt;
                padding:3.0pt 0cm 0cm 0cm">
                <p class="x_MsoNormal"><b><span style="font-size:12.0pt;
                      color:black">From: </span>
                  </b><span style="font-size:12.0pt; color:black"><a class="moz-txt-link-rfc2396E" href="mailto:eprints-tech-bounces@ecs.soton.ac.uk">&lt;eprints-tech-bounces@ecs.soton.ac.uk&gt;</a>
                    on behalf of <a class="moz-txt-link-rfc2396E" href="mailto:eprints-tech@ecs.soton.ac.uk">&quot;eprints-tech@ecs.soton.ac.uk&quot;</a>
                    <a class="moz-txt-link-rfc2396E" href="mailto:eprints-tech@ecs.soton.ac.uk">&lt;eprints-tech@ecs.soton.ac.uk&gt;</a><br>
                    <b>Reply to: </b><a class="moz-txt-link-rfc2396E" href="mailto:eprints-tech@ecs.soton.ac.uk">&quot;eprints-tech@ecs.soton.ac.uk&quot;</a>
                    <a class="moz-txt-link-rfc2396E" href="mailto:eprints-tech@ecs.soton.ac.uk">&lt;eprints-tech@ecs.soton.ac.uk&gt;</a>, James Kerwin
                    <a class="moz-txt-link-rfc2396E" href="mailto:jkerwin2101@gmail.com">&lt;jkerwin2101@gmail.com&gt;</a><br>
                    <b>Date: </b>Wednesday, 24 February 2021 at 13:41<br>
                    <b>To: </b><a class="moz-txt-link-rfc2396E" href="mailto:eprints-tech@ecs.soton.ac.uk">&quot;eprints-tech@ecs.soton.ac.uk&quot;</a>
                    <a class="moz-txt-link-rfc2396E" href="mailto:eprints-tech@ecs.soton.ac.uk">&lt;eprints-tech@ecs.soton.ac.uk&gt;</a>, David R Newman
                    <a class="moz-txt-link-rfc2396E" href="mailto:drn@ecs.soton.ac.uk">&lt;drn@ecs.soton.ac.uk&gt;</a><br>
                    <b>Subject: </b>Re: [EP-tech] EPrints Security
                    Announcement - February 2020</span></p>
              </div>
              <div>
                <p class="x_MsoNormal">&nbsp;</p>
              </div>
              <div style="border:solid black 1.0pt; padding:1.0pt 4.0pt
                1.0pt 4.0pt; background:#FFFFCC">
                <p style="background:#FFFFCC; border:none; padding:0cm"><span style="font-family:&quot;Arial&quot;,sans-serif;
                    color:black">CAUTION: This mail comes from outside
                    the University. Please consider this before opening
                    attachments, clicking links, or acting on the
                    content.
                  </span><span style="font-family:&quot;Arial&quot;,sans-serif"></span></p>
              </div>
              <div>
                <div>
                  <div style="border:solid #8D3970 1.0pt; padding:9.0pt
                    9.0pt 9.0pt 9.0pt">
                    <p class="x_MsoNormal" style="line-height:16.5pt;
                      background:#F7F9FA"><strong><span style="font-size:10.5pt;
                          font-family:&quot;Calibri&quot;,sans-serif;
                          color:#8D3970">CAUTION:</span></strong><span style="font-size:10.5pt; color:#8D3970"> This
                        e-mail originated outside the University of
                        Southampton. </span></p>
                  </div>
                </div>
                <div>
                  <div>
                    <p class="x_MsoNormal">Hi David, </p>
                    <div>
                      <p class="x_MsoNormal">&nbsp;</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">Thank you very much for
                        bringing this to our attention and providing the
                        solutions.</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">&nbsp;</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">Shamefully, we are still on
                        3.3.14 (I promise we are upgrading this year).
                        The patch mentioned works on 3.3.16 and the page
                        says it might work on earlier versions (a brief
                        look through two of the files suggests they're
                        more or less the same as those for 3.3.16)</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">&nbsp;</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">In my attempt to avoid any
                        problems that could result from &quot;might&quot; are
                        these the files that need altering if I were to
                        do it manually:</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">&nbsp;</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">&nbsp;/cgi/ajax/phrase :
                        CVE-2021-26703</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">/cgi/latex2png :
                        CVE-2021-3342</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">/cgi/toolbox/toolbox :
                        CVE-2021-26704</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">&nbsp;</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">There also appears to be
                        some changes to be made to XML.pm</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">&nbsp;</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">Am I interpreting it
                        correctly where it looks as though latex2png
                        will be left as an empty file (deleted) by the
                        end?</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">&nbsp;</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">I think the page makes it
                        very clear that these are the files that are
                        affected, but I just want to check there aren't
                        any others that the patch addresses. I have
                        looked at the patch, but I try not to
                        underestimate my ability to totally
                        misunderstand the most obvious of things.</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">&nbsp;</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">My plan is to try the
                        command first on a test EPrints server and if it
                        doesn't&nbsp;work, do it manually.<br>
                        <br>
                        Thanks,</p>
                    </div>
                    <div>
                      <p class="x_MsoNormal">James</p>
                    </div>
                  </div>
                  <p class="x_MsoNormal">&nbsp;</p>
                  <div>
                    <div>
                      <p class="x_MsoNormal">On Wed, Feb 24, 2021 at
                        9:27 AM David R Newman via Eprints-tech &lt;<a href="mailto:eprints-tech@ecs.soton.ac.uk" moz-do-not-send="true">eprints-tech@ecs.soton.ac.uk</a>&gt;
                        wrote:</p>
                    </div>
                    <blockquote style="border:none; border-left:solid
                      #CCCCCC 1.0pt; padding:0cm 0cm 0cm 6.0pt;
                      margin-left:4.8pt; margin-right:0cm">
                      <div>
                        <p>Hi all, </p>
                        <div>
                          <div>
                            <p class="x_MsoNormal">EPrints Services was
                              recently made aware of a small number of
                              security vulnerabilities within the
                              EPrints codebase, affecting both EPrints
                              3.4 and EPrints 3.3.</p>
                          </div>
                          <div>
                            <p class="x_MsoNormal">I have created two
                              patch files to fix the vulnerabilities and
                              uploaded them to
                              <a href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Ffiles.eprints.org%2F&amp;data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C8345e1db2f4f4bef1e4008d8d8d666de%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637497762657476516%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=1mrijhvti2jrX7gzGHYdWj7xjTxVdIXEcV10uzeXlqw%3D&amp;reserved=0" originalSrc="http://files.eprints.org/" shash="yrUX40+JROucOQAnXlrHnmZvW/lvEbp0QRIDHygaOOOa/tWj10CEXacd6lx2gwIRo7svJznIAOK2+HapGP4sbfIR1k4bxdXc75BJoiqi5hYqA1JW55t0dLSfPbl2S5mBBJKbJSlwYYilhcNmDK7zCRJ1Ux2uWYi2/sACvXKGyYA=" originalsrc="http://files.eprints.org/" shash="ths8gkwLOTmD4mwBFLTDswbVHTXaNQeZJoQvUIWiLugvcXSR4WOgibgSGe/NbCq8x0hRVtrSSvH4sEF5/Di9HAwhTZgW0y05YdShNCT1C01slCKhlfrXrsn6G6Cm2+p24v7zS5gMeDeL279NIKxAqCFaslas8948rb/NVA8eCV4=" target="_blank" moz-do-not-send="true">
                                files.eprints.org</a>.</p>
                          </div>
                        </div>
                        <div>
                          <p class="x_MsoNormal">&nbsp;</p>
                        </div>
                        <p class="x_MsoNormal">- EPrints 3.4.2 : <a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Ffiles.eprints.org%2F2548%2F&amp;data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C8345e1db2f4f4bef1e4008d8d8d666de%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637497762657476516%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=%2BWkxu50vr3bLG6SHELjgfVa3xRcCqCdib4eKH%2BEgdWU%3D&amp;reserved=0" originalSrc="https://files.eprints.org/2548/" shash="S5N2cOBdob5WUCqunKOlNKGlCyAncbCJY5r3w3kHYtU4rRUMfJVjSOi76SShcdqWBYG9sq6DDOqLdGPNkrr17C0ad8gAKR/9NAkZUCOCE4mJKun7QC9wydTDnMJbw6ZglIrWPmJkj2Y6kVamxLZcmQzSIwEfKA22COyRhywqztk=" originalsrc="https://files.eprints.org/2548/" shash="N+WkpmKEIikkiPa1eQukfzWdd1NkOcznjty0bC9iIFld0EsBVVZ2FYQ8j+dQjqM861gBg/rnl2+iaFEKIlSnJf5M7GPri4u27JjzjILye2gUQ3Ni9YZgOBedXL9O3OMZbks21oOfJJ6mZs2gJ8c3XrPn6t/E4OpvGnyujCqDCnw=" target="_blank" moz-do-not-send="true">
                            https://files.eprints.org/2548/</a> <br>
                          - EPrints 3.3.x : <a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Ffiles.eprints.org%2F2549%2F&amp;data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C8345e1db2f4f4bef1e4008d8d8d666de%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637497762657476516%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=ynFQ2y8GtAx1vPj4X6JbZTNfFsDiuhTzshWipiniBrM%3D&amp;reserved=0" originalSrc="https://files.eprints.org/2549/" shash="ODE/z9CW72YrTN0B4OA2zxkTXo5CYao5ekwCt8QuX/vO/yAtRKQYwW9VblfEOPe4uqsWw39IJggdKXgQieibvuu1V7eNVAQspep3A3VKw/k9SX/LjUPfWGIrDL600FXW7tc5Y1W8jkRLobgGul6B65LLCzxSL+EaPzSY0hpwdbY=" originalsrc="https://files.eprints.org/2549/" shash="zTb+S80Oo0FUM/7qn31nj+yy8HkOjFoIqGA8fumghmWdDJx55mYmXB4WLkXoOzCp+KPuRTHhDzkI2/9sWky2q0+rDOPZpvOvmcfO4qmUlszuuhWzmwWjAcWwgG1dZuNblMv4Ow84RPXps/GstAK+v6Blu9mLFfJgGiTC4YV0mWQ=" target="_blank" moz-do-not-send="true">
                            https://files.eprints.org/2549/</a> <br>
                          <br>
                          The former fixes the EPrints 3.4.2 release and
                          the latter fixes EPrints 3.3 (based on the
                          current HEAD of
                          <a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Feprints%2Feprints&amp;data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C8345e1db2f4f4bef1e4008d8d8d666de%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637497762657486471%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=KR%2BeoxidNhssyIBEnQxZ4mvAEjiD2UxcJVT9M8%2FJi4s%3D&amp;reserved=0" originalSrc="https://github.com/eprints/eprints" shash="rPucZa5jOMT0kkSSmxG73/wxHwMDibFLwalShPSrSH8pf3FEH6lrhwrwOCAtoIomB3srGEodCnmtPR+Da3VhcgBXWAo39QaDc6iK9rFaDg5Yi7kXTiGYPVb8YFHE/rFG8bNMkZ0+1n7Y81NS/4DLvdQZdJaOsSNcGSjJnOhMqwg=" originalsrc="https://github.com/eprints/eprints" shash="XTKPFOL2NiJwTYvUzsIS1obodmlXzcatxn9pSQWq+7DvtAeihoXZqQW8Js1vVjDBBVrf+JED44Kzi0sQSVP+IhkAuUvhF8nIrT8AvQ6cUxd3SjFGlHNPQsIuKtW7JOcS/glz/w0BRoQ6lJ4fvfrzw33drVJWP1umadJSZEi7MaE=" target="_blank" moz-do-not-send="true">
                            https://github.com/eprints/eprints</a>).
                          These links also provide instructions on how
                          to apply the patch file and some more details
                          on the affected files.&nbsp; There are references
                          to the Common Vulnerabilities and Exposure
                          (CVE) IDs but as of now these are yet to be
                          published.&nbsp; All the vulnerabilities identified
                          relate to either Cross-Site Scripting (XSS) or
                          Remote Code Execution (RCE) vulnerabilities.&nbsp;
                          All of these vulnerabilities would require
                          analysis of the codebase to determine an
                          exploit.&nbsp; It is very unlikely that generic
                          tools used to identify vulnerabilities would
                          discover these, as specific knowledge is
                          required.
                          <br>
                          <br>
                          I have also updated to patch these
                          vulnerabilities on both the eprints and
                          eprints3.4 GitHub repositories for the eprints
                          organisation (<a href="https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Feprints&amp;data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C8345e1db2f4f4bef1e4008d8d8d666de%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637497762657486471%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=CG2fbpZe9t8xqiBB0VR2FoZxPYhQilwYXl8XaDXiDIA%3D&amp;reserved=0" originalSrc="https://github.com/eprints" shash="YHVLlNVpZdmDDc3lO35L7BF7C90ipciyC8U8h02d6J8E1psKFncE5YoEbUA8KaQiQyJi48QS73TS1nifj12sVLvQRCfEkF+INl3hz13lJzqPuhVsxEqbDCkphCiTE29J1nJ5wyEqmVmDQjvQ5C5Zw/wOAmpOtYgdtnrl9BsJ+PA=" originalsrc="https://github.com/eprints" shash="atQJJ+cqhBV3vab63zFYFrEtCQo1C4h6tLbbyutmnWqTefHXXKz+6GpgOHp3r9JxQApFn8mwgIs0YQNkstIpqs4dYztI4rBCI0Le61j0j+EzVmupdSU2Mw1gcYqFmKlMeifCA2P0UW9NflRsucE/Y/+rKifZkMy893PKGyOaGeU=" target="_blank" moz-do-not-send="true">https://github.com/eprints</a>).&nbsp;
                          The next release of EPrints 3.4 (3.4.3) will
                          have these security fixes in place.
                          <br>
                          <br>
                          EPrints Services customers both those who
                          EPrints Services host and those that self-host
                          have either been patched or where this has not
                          been possible, informed of the vulnerabilities
                          and how they can be fixed.<br>
                          <br>
                          If you have any follow-up questions please
                          feel free to ask. Hopefully, the CVEs will be
                          published shortly for those interested in more
                          detail.&nbsp; However, they were raised by a third
                          party, who I have only just given go-ahead to
                          make these public.
                          <br>
                          <br>
                          Regards <br>
                          <br>
                          David Newman </p>
                        <div id="x_gmail-m_135838354472599755DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2">
                          <p class="x_MsoNormal">&nbsp;</p>
                          <table class="x_MsoNormalTable" style="border:none; border-top:solid #D3D4DE
                            1.0pt" cellpadding="0" border="1">
                            <tbody>
                              <tr>
                                <td style="width:41.25pt; border:none;
                                  padding:9.75pt .75pt .75pt .75pt" width="55">
                                  <p class="x_MsoNormal"><a href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.avg.com%2Femail-signature%3Futm_medium%3Demail%26utm_source%3Dlink%26utm_campaign%3Dsig-email%26utm_content%3Demailclient&amp;data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C8345e1db2f4f4bef1e4008d8d8d666de%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637497762657496428%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=5Btn1XaC3vasd9TTe%2FBohFKfn%2FGlRbCC4u7aAOpbBs4%3D&amp;reserved=0" originalSrc="http://www.avg.com/email-signature?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient" shash="nBZeG059bF36Qzm9ZVrhcPc6WoxT/HV8s3go6grjDkROEepPy8ipePKGkdR2IUEtHf48fF9EJvBtUJotnF2iypFQmBfRYGS65Hrih9dLyv9rBn7YutMU7mgXubwGX6K2Ky7vo7ybZ4XoQSypmwxYdP4pu7Z00BNhJ9jG28F1z/s=" originalsrc="http://www.avg.com/email-signature?utm_medium=email&amp;utm_source=link&amp;utm_campaign=sig-email&amp;utm_content=emailclient" shash="WygaP03uFimM1dxfizAXvCyOdcKyKV4Q4cD5eRf2oPfN64FKzS8M8S9Ib2Tg8rgC6FtbHjeJpK1wK8E+k0mmXyLXUUazIKXRW4bl6so4nxPzC6i+vjJkdpdnadkN+OffzALzzGvPabslTv+UOArf1BHeXXHnY/ZnsRseGp/ZMK4=" target="_blank" moz-do-not-send="true"><span style="color:windowtext;
                                        text-decoration:none"><span style="color:blue;
                                          border:solid windowtext 1.0pt;
                                          padding:0cm"><img id="x__x0000_i1025" alt="Image removed by
                                            sender." style="width:.4791in;
                                            height:.302in" data-outlook-trace="F:0|T:1" src="cid:~WRD0000.jpg" moz-do-not-send="true" width="46" height="29" border="0"></span></span></a></p>
                                </td>
                                <td style="width:352.5pt; border:none;
                                  padding:9.0pt .75pt .75pt .75pt" width="470">
                                  <p class="x_MsoNormal" style="line-height:13.5pt"><span style="font-size:10.0pt;
                                      font-family:&quot;Arial&quot;,sans-serif;
                                      color:#41424E">Virus-free.
                                      <a href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.avg.com%2Femail-signature%3Futm_medium%3Demail%26utm_source%3Dlink%26utm_campaign%3Dsig-email%26utm_content%3Demailclient&amp;data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C8345e1db2f4f4bef1e4008d8d8d666de%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637497762657496428%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=5Btn1XaC3vasd9TTe%2FBohFKfn%2FGlRbCC4u7aAOpbBs4%3D&amp;reserved=0" originalSrc="http://www.avg.com/email-signature?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient" shash="nBZeG059bF36Qzm9ZVrhcPc6WoxT/HV8s3go6grjDkROEepPy8ipePKGkdR2IUEtHf48fF9EJvBtUJotnF2iypFQmBfRYGS65Hrih9dLyv9rBn7YutMU7mgXubwGX6K2Ky7vo7ybZ4XoQSypmwxYdP4pu7Z00BNhJ9jG28F1z/s=" originalsrc="http://www.avg.com/email-signature?utm_medium=email&amp;utm_source=link&amp;utm_campaign=sig-email&amp;utm_content=emailclient" shash="WygaP03uFimM1dxfizAXvCyOdcKyKV4Q4cD5eRf2oPfN64FKzS8M8S9Ib2Tg8rgC6FtbHjeJpK1wK8E+k0mmXyLXUUazIKXRW4bl6so4nxPzC6i+vjJkdpdnadkN+OffzALzzGvPabslTv+UOArf1BHeXXHnY/ZnsRseGp/ZMK4=" target="_blank" moz-do-not-send="true">
                                        <span style="color:#4453EA">www.avg.com</span></a>
                                    </span></p>
                                </td>
                              </tr>
                            </tbody>
                          </table>
                        </div>
                      </div>
                      <p class="x_MsoNormal">*** Options: <a href="http://mailman.ecs.soton.ac.uk/mailman/listinfo/eprints-tech" target="_blank" moz-do-not-send="true">
http://mailman.ecs.soton.ac.uk/mailman/listinfo/eprints-tech</a><br>
                        *** Archive: <a href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.eprints.org%2Ftech.php%2F&amp;data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C8345e1db2f4f4bef1e4008d8d8d666de%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637497762657506385%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=nkQWUQglna8xqpo9zjYf4urxCdhoqoIH8ZCaN9vWMoY%3D&amp;reserved=0" originalSrc="http://www.eprints.org/tech.php/" shash="KXs8ZTJnskkTqzqYAOHqUktnaga+t7hFRWI1wU5gODDKQdAXBMRCiHE51X+m1Y7eoukM5Dqn+S0H3vLyQzB0I3tXbkaJ1BtLHLHami0uBjedDmLqD77d6nzNkLNTvySaUC3/NmMt3QuvoR5Wy8lESfu1y0HrAdwoRbraFrmNtQI=" originalsrc="http://www.eprints.org/tech.php/" shash="IW+m3yzd4VwWw/ve1rWJAhOsRyjfgTOfKlWa0P2WwOo35aZkut1c3nRbSR3AZ+ju/pSUMJZ9f7K3CBhqRiDgOvVqiiN9kPJpYEo4Z42Var4bq84vmeQiR15T3rIqP4RtZ6nfHVHhO5uRcv/zvWXYvmco3cLE3CHKb7t9rSI6Umg=" target="_blank" moz-do-not-send="true">
                          http://www.eprints.org/tech.php/</a><br>
                        *** EPrints community wiki: <a href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwiki.eprints.org%2F&amp;data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C8345e1db2f4f4bef1e4008d8d8d666de%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637497762657506385%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=d1gx8sJZGwEfq7%2Fdtq4cSozmlC%2BvzC0kCpBKi6FjOGk%3D&amp;reserved=0" originalSrc="http://wiki.eprints.org/" shash="OJ0MqXv4zJxhR7W1TaRN/+AfcfQy+XofbVPjdMlL6IrPwWOEqpU9v5TotuzLvmDXmog6mrTjDUD/BxIvPKeVanDpRlD1ur5pHg9HmcBkDZmZFfdUYUIQFGo5AgRnRMRFYKvMwmUNaPK7P17jdw2wI6gNVkLJLYTOOTzyOwsdtso=" originalsrc="http://wiki.eprints.org/" shash="b+Uagjhf08Hy8lDLayiJsw6a0xMWQsc/ctw9YFy4BPrah7GNwR9UIvK9ZK2CNCnWSAxWUvlzDQnu7Xhg31NXuWzj9OLqbNrCtYJeiqr1RIcVnGbHJsCKVUmNOqurJLrL/Z5FoUNiNLvgEPlkVdRY1aGvIS5P1nJjwYWW2qAMOqI=" target="_blank" moz-do-not-send="true">
                          http://wiki.eprints.org/</a></p>
                    </blockquote>
                  </div>
                </div>
              </div>
            </div>
          </div>
        </div>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <pre class="moz-quote-pre" wrap="">*** Options: <a class="moz-txt-link-freetext" href="http://mailman.ecs.soton.ac.uk/mailman/listinfo/eprints-tech">http://mailman.ecs.soton.ac.uk/mailman/listinfo/eprints-tech</a>
*** Archive: <a class="moz-txt-link-freetext" href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.eprints.org%2Ftech.php%2F&amp;data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C8345e1db2f4f4bef1e4008d8d8d666de%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637497762657506385%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=nkQWUQglna8xqpo9zjYf4urxCdhoqoIH8ZCaN9vWMoY%3D&amp;reserved=0" originalSrc="http://www.eprints.org/tech.php/" shash="KXs8ZTJnskkTqzqYAOHqUktnaga+t7hFRWI1wU5gODDKQdAXBMRCiHE51X+m1Y7eoukM5Dqn+S0H3vLyQzB0I3tXbkaJ1BtLHLHami0uBjedDmLqD77d6nzNkLNTvySaUC3/NmMt3QuvoR5Wy8lESfu1y0HrAdwoRbraFrmNtQI=">http://www.eprints.org/tech.php/</a>
*** EPrints community wiki: <a class="moz-txt-link-freetext" href="https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwiki.eprints.org%2F&amp;data=04%7C01%7Ceprints-tech%40ecs.soton.ac.uk%7C8345e1db2f4f4bef1e4008d8d8d666de%7C4a5378f929f44d3ebe89669d03ada9d8%7C0%7C0%7C637497762657516339%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=%2FfNEZb3v83XJgl9OIHdHSzHmdfuQICUjm7Sl6xKKfbU%3D&amp;reserved=0" originalSrc="http://wiki.eprints.org/" shash="lo+wzptFgZRHLLGrQND7WFR2eWeWaSJCk1Ufl7nNX7DrO1ahiY2YbVALh+DZOpxdWTfI98mtG+mep40j++472WF7iQw//ZztW9zAJi1khMGGrX0ntmGmZDi3dGUB6PjeDtLn3QNYY0HbUp67MznqOjRJrv7krq2gfEP21ReUDFM=">http://wiki.eprints.org/</a></pre>
    </blockquote>
    <pre class="moz-signature" cols="72">-- 
Christopher Gutteridge <a class="moz-txt-link-rfc2396E" href="mailto:totl@soton.ac.uk">&lt;totl@soton.ac.uk&gt;</a> 
You should read our team blog at <a class="moz-txt-link-freetext" href="http://blog.soton.ac.uk/webteam/">http://blog.soton.ac.uk/webteam/</a></pre>
  </body>
</html>