XML External Entity Reference in apache jena
Critical severity
GitHub Reviewed
Published
May 6, 2022
to the GitHub Advisory Database
•
Updated Oct 13, 2023
Description
Published by the National Vulnerability Database
May 5, 2022
Published to the GitHub Advisory Database
May 6, 2022
Reviewed
May 24, 2022
Last updated
Oct 13, 2023
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 only. Apache Jena 4.2.x and 4.3.x do not allow external entities.
References