Описание
File access paths in configuration files uploaded by users with administrator access are not validated.
This issue affects Apache Jena version up to 5.4.0.
Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload.
A file path validation flaw has been discovered in Apache Jena. This flaw allows users with administrative access to upload arbitrary configurations.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
AMQ Clients | jena-arq | Fix deferred | ||
AMQ Clients | jena-base | Fix deferred | ||
AMQ Clients | jena-core | Fix deferred | ||
AMQ Clients | jena-iri | Fix deferred | ||
AMQ Clients | jena-shaded-guava | Fix deferred | ||
Red Hat build of Apicurio Registry 3 | jena-base | Fix deferred | ||
Red Hat build of Apicurio Registry 3 | jena-core | Fix deferred | ||
Red Hat build of Apicurio Registry 3 | jena-iri | Fix deferred | ||
Red Hat build of Apicurio Registry 3 | jena-shaded-guava | Fix deferred | ||
Red Hat Data Grid 8 | jena-arq | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload.
File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload.
File access paths in configuration files uploaded by users with admini ...
Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access
EPSS
6.5 Medium
CVSS3