A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2022-05-05T08:40:09

Updated: 2024-08-03T06:10:56.881Z

Reserved: 2022-04-09T00:00:00

Link: CVE-2022-28890

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-05-05T09:15:08.140

Modified: 2023-10-25T17:01:16.697

Link: CVE-2022-28890

cve-icon Redhat

No data.