NA

CVE-2023-22665

Published: 25/04/2023 Updated: 21/01/2024
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

There is insufficient checking of user queries in Apache Jena versions 4.7.0 and previous versions, when invoking custom scripts. It allows a remote user to execute arbitrary javascript via a SPARQL query.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache jena

Vendor Advisories

Debian Bug report logs - #1035952 apache-jena: CVE-2023-22665 Package: src:apache-jena; Maintainer for src:apache-jena is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Thu, 11 May 2023 15:45:04 UTC Severity: important Tags: security, ups ...