CVE-2025-50151

File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:jena:*:*:*:*:*:*:*:*

History

04 Nov 2025, 22:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/07/21/2 -

29 Jul 2025, 14:22

Type Values Removed Values Added
Summary
  • (es) Las rutas de acceso a los archivos de configuración cargados por usuarios con acceso de administrador no se validan. Este problema afecta a Apache Jena hasta la versión 5.4.0. Se recomienda actualizar a la versión 5.5.0, que no permite la carga de configuraciones arbitrarias.
CPE cpe:2.3:a:apache:jena:*:*:*:*:*:*:*:*
First Time Apache jena
Apache
References () https://lists.apache.org/thread/12gks5z40gh9bszn1xk8mz34gz586xss - () https://lists.apache.org/thread/12gks5z40gh9bszn1xk8mz34gz586xss - Issue Tracking, Vendor Advisory

21 Jul 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

21 Jul 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-21 10:15

Updated : 2025-11-04 22:16


NVD link : CVE-2025-50151

Mitre link : CVE-2025-50151

CVE.ORG link : CVE-2025-50151


JSON object : View

Products Affected

apache

  • jena
CWE
CWE-20

Improper Input Validation