CVE-2025-50151
Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access
7.2
HIGH
CVSS 3.1
EPSS 0.94%
描述
File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload.
如何修補 CVE-2025-50151
要修補 CVE-2025-50151,請將受影響套件升級到下列已修補版本。
- —未列出修補版本
- —升級至 5.5.0 或更新版本
CVE-2025-50151 正在被利用嗎?
低 — EPSS 為 0.9%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0
- from 0, < 5.5.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.2 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |