CVE-2023-32200
HIGH8.8EPSS 0.94%Apache Jena Expression Language Injection vulnerability
Published: 7/12/2023Modified: 4/28/2026
Description
There is insufficient restrictions of called script functions in Apache Jena versions 4.8.0 and earlier. It allows a remote user to execute javascript via a SPARQL query. This issue affects Apache Jena: from 3.7.0 through 4.8.0.
Affected packages (2)
- Debian/apache-jenafrom 0
- Maven/org.apache.jena:jena>= 3.7.0, < 4.9.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
References (6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2023-32200
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2023-32200
- PATCHhttps://github.com/apache/jena
- WEBhttps://jena.apache.org/about_jena/security-advisories.html#cve-2023-32200---exposure-of-execution-in-script-engine-expressions
- WEBhttps://lists.apache.org/thread/7hg0t2kws3fyr75dl7lll8389xzzc46z
- WEBhttps://www.cve.org/CVERecord?id=CVE-2023-22665