Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-22665

Опубликовано: 25 апр. 2023
Источник: debian

Описание

There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to execute arbitrary javascript via a SPARQL query.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache-jenafixed4.9.0-1package
apache-jenaignoredbookwormpackage

Примечания

  • https://lists.apache.org/thread/s0dmpsxcwqs57l4qfs415klkgmhdxq7s

Связанные уязвимости

CVSS3: 5.4
ubuntu
почти 3 года назад

There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to execute arbitrary javascript via a SPARQL query.

CVSS3: 5.4
nvd
почти 3 года назад

There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to execute arbitrary javascript via a SPARQL query.

CVSS3: 5.4
github
почти 3 года назад

Arbitrary javascript injection in Apache Jena