Description
A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
Users are advised to upgrade to Apache Jena 4.2.0 or later.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2007 | A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server. |
Github GHSA |
GHSA-7rp6-w7mg-h8rw | XML External Entity Reference in Apache Jena |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T02:06:40.799Z
Reserved: 2021-08-17T00:00:00.000Z
Link: CVE-2021-39239
No data.
Status : Modified
Published: 2021-09-16T15:15:07.527
Modified: 2024-11-21T06:18:59.310
Link: CVE-2021-39239
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA