Lucene search

K
osvGoogleOSV:GHSA-GCHV-364H-R896
HistoryMay 06, 2022 - 12:00 a.m.

XML External Entity Reference in apache jena

2022-05-0600:00:53
Google
osv.dev
15
apache jena
xml
vulnerability
rdf
parser
dtd
external entities

AI Score

9.3

Confidence

High

EPSS

0.029

Percentile

90.8%

A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 only. Apache Jena 4.2.x and 4.3.x do not allow external entities.

AI Score

9.3

Confidence

High

EPSS

0.029

Percentile

90.8%