A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-3938 A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.
Github GHSA Github GHSA GHSA-gchv-364h-r896 XML External Entity Reference in apache jena
Fixes

Solution

No solution given by the vendor.


Workaround

Users are advised to upgrade to Apache Jena 4.5.0 or later.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-03T06:10:56.881Z

Reserved: 2022-04-09T00:00:00

Link: CVE-2022-28890

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-05T09:15:08.140

Modified: 2024-11-21T06:58:08.750

Link: CVE-2022-28890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.