Lucene search

K
cvelistApacheCVELIST:CVE-2022-28890
HistoryMay 05, 2022 - 8:40 a.m.

CVE-2022-28890 Processing external DTDs

2022-05-0508:40:09
apache
www.cve.org
6
apache jena
rdf/xml
vulnerability

AI Score

9.5

Confidence

High

EPSS

0.029

Percentile

90.8%

A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.

CNA Affected

[
  {
    "product": "Apache Jena",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "4.4.0",
        "status": "affected",
        "version": "Apache Jena",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

9.5

Confidence

High

EPSS

0.029

Percentile

90.8%