Описание
Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in the disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted RDF file.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| rdf4j | unfixed | package | ||
| rdf4j | no-dsa | trixie | package | |
| rdf4j | postponed | bookworm | package |
Примечания
https://github.com/eclipse-rdf4j/rdf4j/issues/1056
Fixed by: https://github.com/eclipse-rdf4j/rdf4j/commit/50f2f51950227a4ec595a2922d81da487aba5135 (2.4.1)
When fixing this issue make sure to make the fix complete and not open CVE-2026-15803
Cf. https://gitlab.eclipse.org/security/cve-assignment/-/work_items/175
Связанные уязвимости
Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in the disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted RDF file.