CVE-2025-50151

HIGH7.2EPSS 0.71%

Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access

發布日:2025/7/21修改日:2026/4/28

描述

File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

參考連結(5)