A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain page views. This issue affects Apache Jena Fuseki from version 2.0.0 to version 4.0.0 (inclusive).
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-phwj-86vx-cfjc Cross-site scripting in Apache Jena Fuseki
Fixes

Solution

No solution given by the vendor.


Workaround

Users are advised to upgrade to Apache Jena 4.1.0 or later.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.15929}

epss

{'score': 0.10411}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-03T23:42:20.271Z

Reserved: 2021-05-19T00:00:00

Link: CVE-2021-33192

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-07-05T10:15:08.457

Modified: 2024-11-21T06:08:29.087

Link: CVE-2021-33192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.