File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload.
History

Tue, 22 Jul 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache jena
Vendors & Products Apache
Apache jena

Mon, 21 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Jul 2025 09:45:00 +0000

Type Values Removed Values Added
Description File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload.
Title Apache Jena: Configuration files uploaded by administrative users are not check properly
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-07-21T09:32:30.334Z

Updated: 2025-07-21T14:41:06.294Z

Reserved: 2025-06-13T16:13:26.895Z

Link: CVE-2025-50151

cve-icon Vulnrichment

Updated: 2025-07-21T14:40:28.861Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-21T10:15:25.837

Modified: 2025-07-22T13:06:07.260

Link: CVE-2025-50151

cve-icon Redhat

No data.